Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0073E180 GetFileAttributesW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
35_2_0073E180 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0074A187 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
35_2_0074A187 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0074A2E4 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
35_2_0074A2E4 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0074A66E FindFirstFileW,Sleep,FindNextFileW,FindClose, |
35_2_0074A66E |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0074686D FindFirstFileW,FindNextFileW,FindClose, |
35_2_0074686D |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0073E9BA GetFileAttributesW,FindFirstFileW,FindClose, |
35_2_0073E9BA |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_007474F0 FindFirstFileW,FindClose, |
35_2_007474F0 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_00747591 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime, |
35_2_00747591 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0073DE32 GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,FindFirstFileW,DeleteFileW,CompareStringW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
35_2_0073DE32 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_014A3ECD FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, |
35_2_014A3ECD |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_014A17FD GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, |
35_2_014A17FD |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_014A3FD5 FindFirstFileA,GetLastError, |
35_2_014A3FD5 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CEA187 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
38_2_00CEA187 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CDE180 GetFileAttributesW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
38_2_00CDE180 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CEA2E4 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
38_2_00CEA2E4 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CEA66E FindFirstFileW,Sleep,FindNextFileW,FindClose, |
38_2_00CEA66E |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CE686D FindFirstFileW,FindNextFileW,FindClose, |
38_2_00CE686D |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CDE9BA GetFileAttributesW,FindFirstFileW,FindClose, |
38_2_00CDE9BA |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CE74F0 FindFirstFileW,FindClose, |
38_2_00CE74F0 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CE7591 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime, |
38_2_00CE7591 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CDDE32 GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,FindFirstFileW,DeleteFileW,CompareStringW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
38_2_00CDDE32 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_01653765 FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, |
38_2_01653765 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_01651095 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, |
38_2_01651095 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_0165386D FindFirstFileA,GetLastError, |
38_2_0165386D |
Source: MSBuild.exe, 00000025.00000002.2940433393.0000000001459000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://152.89.198.124/8bdDsv3dk2FF/index.php |
Source: MSBuild.exe, 00000025.00000002.2940433393.0000000001418000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://152.89.198.124/8bdDsv3dk2FF/index.phped |
Source: MSBuild.exe, 00000025.00000002.2940433393.0000000001447000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://152.89.198.124/8bdDsv3dk2FF/index.phpp |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://crl.certum.pl/cscasha2.crl0q |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://crl.certum.pl/ctnca.crl0k |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0 |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0 |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://crl.globalsign.com/root-r3.crl0c |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://crl.globalsign.net/root-r3.crl0 |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0# |
Source: Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://cscasha2.ocsp-ce |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://cscasha2.ocsp-certum.com04 |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp.sectigo.com0 |
Source: Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp.us |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp2.globalsign.com/gstimestampingsha2g20 |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://repository.certum |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://repository.certum.pl/cscasha2.cer0 |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://repository.certum.pl/ctnca.cer09 |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08 |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0 |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://subca.ocsp-certum.com01 |
Source: Updater.exe, 0000001C.00000000.1722434360.00000000007A5000.00000002.00000001.01000000.0000000B.sdmp, Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2237879477.00000000007A5000.00000002.00000001.01000000.0000000B.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000000.2362895220.0000000000D45000.00000002.00000001.01000000.0000000D.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://www.autoitscript.com/autoit3/X |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://www.certum.pl/CPS0 |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://jrsoftware.org/ |
Source: Reminder.exe, 00000000.00000000.1678698708.0000000000861000.00000020.00000001.01000000.00000003.sdmp |
String found in binary or memory: https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://jrsoftware.org0 |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://sectigo.com/CPS0D |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://www.autoitscript.com/autoit3/ |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://www.certum.pl/CPS0 |
Source: AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://www.globalsign.com/repository/06 |
Source: Reminder.exe, 00000000.00000003.1680434117.0000000002F70000.00000004.00001000.00020000.00000000.sdmp, Reminder.exe, 00000000.00000003.1680920376.000000007F2BB000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000000.1682457089.0000000000A41000.00000020.00000001.01000000.00000004.sdmp, Reminder.tmp, 00000003.00000000.1688593494.0000000000F1D000.00000020.00000001.01000000.00000009.sdmp |
String found in binary or memory: https://www.innosetup.com/ |
Source: Reminder.exe, 00000000.00000003.1680434117.0000000002F70000.00000004.00001000.00020000.00000000.sdmp, Reminder.exe, 00000000.00000003.1680920376.000000007F2BB000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000000.1682457089.0000000000A41000.00000020.00000001.01000000.00000004.sdmp, Reminder.tmp, 00000003.00000000.1688593494.0000000000F1D000.00000020.00000001.01000000.00000009.sdmp |
String found in binary or memory: https://www.remobjects.com/ps |
Source: unknown |
Network traffic detected: HTTP traffic on port 57886 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57943 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57725 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57989 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57966 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57805 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57748 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57931 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57908 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57977 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57851 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57794 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57816 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57759 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57919 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57840 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57875 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57714 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57932 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57827 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57852 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57772 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57885 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57990 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57897 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57954 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57874 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57863 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57965 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57804 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57747 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57896 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57873 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57712 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57850 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57829 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57735 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57758 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57838 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57784 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57910 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57956 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57773 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57921 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57967 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57724 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57988 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57806 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57861 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57955 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57978 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57762 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57817 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57922 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57746 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57895 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57933 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57828 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57757 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57796 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57884 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57944 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57839 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57785 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57905 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57848 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57928 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57825 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57797 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57940 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57774 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57860 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57883 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57872 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57763 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57952 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57734 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57837 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57745 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57802 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57871 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57894 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57974 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57733 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57756 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57798 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57939 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57813 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57987 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57786 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57906 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57849 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57962 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57775 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57917 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57722 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57951 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57764 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57787 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57930 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57953 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57976 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57918 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57815 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57721 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57985 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57744 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57847 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57929 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57826 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57755 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57776 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57882 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57858 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57942 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57907 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57720 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57997 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57859 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57941 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57881 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57964 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57836 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57803 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57765 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57788 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57870 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57975 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57732 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57799 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57814 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57986 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57743 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57809 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57806 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57927 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57805 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57926 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57929 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57807 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57928 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57802 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57923 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57801 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57922 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57804 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57925 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57803 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57924 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57754 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57777 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57800 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57921 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57811 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57857 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57834 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57937 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57914 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49675 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57822 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57742 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57817 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57938 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57816 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57937 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57819 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57818 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57939 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57813 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57934 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57812 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57933 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57815 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57960 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57814 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57925 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57935 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57868 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57930 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57811 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57932 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57810 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57931 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57731 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57995 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57892 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57766 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57789 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57869 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57828 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57949 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57827 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57948 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57959 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57984 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57829 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57945 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57823 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57944 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57826 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57825 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57926 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57946 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57820 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57903 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57941 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57940 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57822 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57943 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57821 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57942 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57753 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57950 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57730 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57971 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57891 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57718 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57839 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57717 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57838 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57959 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57719 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57714 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57948 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57956 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57834 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57955 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57719 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57716 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57837 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57958 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57996 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57715 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57836 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57957 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57831 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57952 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57778 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57830 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57951 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57712 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57833 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57954 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57832 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57953 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57840 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57961 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57810 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57960 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57880 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57741 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57844 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57982 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57867 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57973 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57950 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57729 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57717 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57801 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57790 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57904 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57752 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57812 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57833 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57915 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57879 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57823 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57908 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57800 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57905 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57904 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57907 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57906 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57949 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57901 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57961 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57900 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57903 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57718 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57902 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57779 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57791 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57916 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57740 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57919 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57916 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57927 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57915 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57845 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57918 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57917 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57983 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57912 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57911 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57914 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57913 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57910 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57856 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57938 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57972 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57890 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57768 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57739 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57716 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57819 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57957 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57769 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57768 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57889 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57765 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57886 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57764 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57885 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57888 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57766 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57887 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57772 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57771 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57892 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57774 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57895 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57773 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57894 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57770 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57891 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57890 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57992 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57780 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57981 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57843 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57889 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57900 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57779 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57776 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57897 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57775 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57896 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57778 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57899 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57777 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57898 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57782 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57728 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57785 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57784 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57946 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57781 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57780 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57854 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57911 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57787 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57786 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57789 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57888 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57788 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57727 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57794 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57793 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57796 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57790 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57807 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57832 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57855 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57945 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57792 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57968 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57791 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57769 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57912 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57818 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57923 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57866 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57798 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57797 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57792 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57799 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57750 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57993 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57877 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57934 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57781 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57821 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57729 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57728 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57849 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57725 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57770 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57924 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57967 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57724 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57845 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57966 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57727 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57848 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57969 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57726 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57847 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57968 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57721 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57842 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57720 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57841 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57962 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57793 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57844 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57965 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57722 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57843 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57901 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57964 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57970 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57730 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57851 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57972 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57850 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57971 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57809 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57841 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57853 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57876 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57761 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57899 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57738 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57739 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57857 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57978 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57735 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57830 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57856 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57977 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57738 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57859 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57864 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57737 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57858 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57732 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57853 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57974 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57731 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57852 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57973 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57734 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57855 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57976 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57733 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57854 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57975 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57860 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57981 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57980 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57741 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57983 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57740 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57861 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57982 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57970 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57991 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57749 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57980 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57737 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57842 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57747 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57865 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57868 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57989 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57746 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57867 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57988 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57749 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57748 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57869 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57743 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57864 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57985 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57742 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57863 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57984 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57745 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57866 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57987 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57744 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57865 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57986 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57750 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57871 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57992 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57870 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57991 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57752 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57873 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57872 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57993 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57990 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57782 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57935 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57715 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57820 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 57958 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57758 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 57879 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006D7070 |
35_2_006D7070 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006E3AD9 |
35_2_006E3AD9 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0070E32F |
35_2_0070E32F |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006F24CA |
35_2_006F24CA |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_00706599 |
35_2_00706599 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0075C844 |
35_2_0075C844 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006F29E3 |
35_2_006F29E3 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006FC9C0 |
35_2_006FC9C0 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006ECBF0 |
35_2_006ECBF0 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_00706C09 |
35_2_00706C09 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_00742D81 |
35_2_00742D81 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006DCE20 |
35_2_006DCE20 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006DEE00 |
35_2_006DEE00 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006F2F23 |
35_2_006F2F23 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006EF0DA |
35_2_006EF0DA |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_00739168 |
35_2_00739168 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0076525A |
35_2_0076525A |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006ED37F |
35_2_006ED37F |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006F7746 |
35_2_006F7746 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006F1964 |
35_2_006F1964 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006F7975 |
35_2_006F7975 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006F7BD2 |
35_2_006F7BD2 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006DDC70 |
35_2_006DDC70 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_00709D1E |
35_2_00709D1E |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_006F1FC1 |
35_2_006F1FC1 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_014B89A9 |
35_2_014B89A9 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_014B89A2 |
35_2_014B89A2 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C77070 |
38_2_00C77070 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C83AD9 |
38_2_00C83AD9 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CAE32F |
38_2_00CAE32F |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C924CA |
38_2_00C924CA |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CA6599 |
38_2_00CA6599 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CFC844 |
38_2_00CFC844 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C9C9C0 |
38_2_00C9C9C0 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C929E3 |
38_2_00C929E3 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C8CBF0 |
38_2_00C8CBF0 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CA6C09 |
38_2_00CA6C09 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CE2D81 |
38_2_00CE2D81 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C7EE00 |
38_2_00C7EE00 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C7CE20 |
38_2_00C7CE20 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C92F23 |
38_2_00C92F23 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C8F0DA |
38_2_00C8F0DA |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CD9168 |
38_2_00CD9168 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00D0525A |
38_2_00D0525A |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C8D37F |
38_2_00C8D37F |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C97746 |
38_2_00C97746 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C91964 |
38_2_00C91964 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C97975 |
38_2_00C97975 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C97BD2 |
38_2_00C97BD2 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C7DC70 |
38_2_00C7DC70 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CA9D1E |
38_2_00CA9D1E |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00C91FC1 |
38_2_00C91FC1 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_01668241 |
38_2_01668241 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_0166823A |
38_2_0166823A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_0040B650 |
41_2_0040B650 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_004051D0 |
41_2_004051D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_004531E2 |
41_2_004531E2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_0044623A |
41_2_0044623A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_0042E2C5 |
41_2_0042E2C5 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_004312A3 |
41_2_004312A3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_0045C476 |
41_2_0045C476 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_004064C0 |
41_2_004064C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_00405480 |
41_2_00405480 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_0045C596 |
41_2_0045C596 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_00433644 |
41_2_00433644 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_00405730 |
41_2_00405730 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_00449780 |
41_2_00449780 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_00453969 |
41_2_00453969 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_0045A9D8 |
41_2_0045A9D8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_0042EAB4 |
41_2_0042EAB4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_00441C90 |
41_2_00441C90 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 41_2_00441D3D |
41_2_00441D3D |
Source: unknown |
Process created: C:\Users\user\Desktop\Reminder.exe "C:\Users\user\Desktop\Reminder.exe" |
|
Source: C:\Users\user\Desktop\Reminder.exe |
Process created: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp "C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp" /SL5="$20434,1768989,845824,C:\Users\user\Desktop\Reminder.exe" |
|
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Process created: C:\Users\user\Desktop\Reminder.exe "C:\Users\user\Desktop\Reminder.exe" /VERYSILENT |
|
Source: C:\Users\user\Desktop\Reminder.exe |
Process created: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp "C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp" /SL5="$20442,1768989,845824,C:\Users\user\Desktop\Reminder.exe" /VERYSILENT |
|
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq wrsa.exe" /FO CSV /NH | find /I "wrsa.exe" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq wrsa.exe" /FO CSV /NH |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\find.exe find /I "wrsa.exe" |
|
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq opssvc.exe" /FO CSV /NH | find /I "opssvc.exe" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq opssvc.exe" /FO CSV /NH |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\find.exe find /I "opssvc.exe" |
|
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq avastui.exe" /FO CSV /NH | find /I "avastui.exe" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq avastui.exe" /FO CSV /NH |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\find.exe find /I "avastui.exe" |
|
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq avgui.exe" /FO CSV /NH | find /I "avgui.exe" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq avgui.exe" /FO CSV /NH |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\find.exe find /I "avgui.exe" |
|
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq nswscsvc.exe" /FO CSV /NH | find /I "nswscsvc.exe" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq nswscsvc.exe" /FO CSV /NH |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\find.exe find /I "nswscsvc.exe" |
|
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq sophoshealth.exe" /FO CSV /NH | find /I "sophoshealth.exe" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq sophoshealth.exe" /FO CSV /NH |
|
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Process created: C:\Users\user\AppData\Local\friend\Updater.exe "C:\Users\user\AppData\Local\friend\\Updater.exe" "C:\Users\user\AppData\Local\friend\\yeorling.csv" |
|
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c ping -n 5 127.0.0.1 >nul && updater.exe C:\ProgramData\\huv9LF4.a3x && del C:\ProgramData\\huv9LF4.a3x |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\PING.EXE ping -n 5 127.0.0.1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\friend\Updater.exe updater.exe C:\ProgramData\\huv9LF4.a3x |
|
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
|
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
|
Source: unknown |
Process created: C:\edgheaa\AutoIt3.exe "C:\edgheaa\AutoIt3.exe" C:\edgheaa\fkccfcd.a3x |
|
Source: C:\edgheaa\AutoIt3.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
|
Source: C:\edgheaa\AutoIt3.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
|
Source: C:\edgheaa\AutoIt3.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
|
Source: unknown |
Process created: C:\edgheaa\AutoIt3.exe "C:\edgheaa\AutoIt3.exe" C:\edgheaa\fkccfcd.a3x |
|
Source: C:\edgheaa\AutoIt3.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
|
Source: C:\edgheaa\AutoIt3.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
|
Source: C:\Users\user\Desktop\Reminder.exe |
Process created: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp "C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp" /SL5="$20434,1768989,845824,C:\Users\user\Desktop\Reminder.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Process created: C:\Users\user\Desktop\Reminder.exe "C:\Users\user\Desktop\Reminder.exe" /VERYSILENT |
Jump to behavior |
Source: C:\Users\user\Desktop\Reminder.exe |
Process created: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp "C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp" /SL5="$20442,1768989,845824,C:\Users\user\Desktop\Reminder.exe" /VERYSILENT |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq wrsa.exe" /FO CSV /NH | find /I "wrsa.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq opssvc.exe" /FO CSV /NH | find /I "opssvc.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq avastui.exe" /FO CSV /NH | find /I "avastui.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq avgui.exe" /FO CSV /NH | find /I "avgui.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq nswscsvc.exe" /FO CSV /NH | find /I "nswscsvc.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq sophoshealth.exe" /FO CSV /NH | find /I "sophoshealth.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Process created: C:\Users\user\AppData\Local\friend\Updater.exe "C:\Users\user\AppData\Local\friend\\Updater.exe" "C:\Users\user\AppData\Local\friend\\yeorling.csv" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq wrsa.exe" /FO CSV /NH |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\find.exe find /I "wrsa.exe" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq opssvc.exe" /FO CSV /NH |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\find.exe find /I "opssvc.exe" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq avastui.exe" /FO CSV /NH |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\find.exe find /I "avastui.exe" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq avgui.exe" /FO CSV /NH |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\find.exe find /I "avgui.exe" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq nswscsvc.exe" /FO CSV /NH |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\find.exe find /I "nswscsvc.exe" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq sophoshealth.exe" /FO CSV /NH |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\find.exe find /I "sophoshealth.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c ping -n 5 127.0.0.1 >nul && updater.exe C:\ProgramData\\huv9LF4.a3x && del C:\ProgramData\\huv9LF4.a3x |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\PING.EXE ping -n 5 127.0.0.1 |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\friend\Updater.exe updater.exe C:\ProgramData\\huv9LF4.a3x |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Jump to behavior |
Source: C:\Users\user\Desktop\Reminder.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Reminder.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: wtsapi32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: rstrtmgr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Reminder.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Reminder.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: wtsapi32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: rstrtmgr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: sfc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: explorerframe.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\find.exe |
Section loaded: ulib.dll |
Jump to behavior |
Source: C:\Windows\System32\find.exe |
Section loaded: fsutilext.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\find.exe |
Section loaded: ulib.dll |
Jump to behavior |
Source: C:\Windows\System32\find.exe |
Section loaded: fsutilext.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\find.exe |
Section loaded: ulib.dll |
Jump to behavior |
Source: C:\Windows\System32\find.exe |
Section loaded: fsutilext.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\find.exe |
Section loaded: ulib.dll |
Jump to behavior |
Source: C:\Windows\System32\find.exe |
Section loaded: fsutilext.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\find.exe |
Section loaded: ulib.dll |
Jump to behavior |
Source: C:\Windows\System32\find.exe |
Section loaded: fsutilext.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\tasklist.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\find.exe |
Section loaded: ulib.dll |
Jump to behavior |
Source: C:\Windows\System32\find.exe |
Section loaded: fsutilext.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: pcacli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0073E180 GetFileAttributesW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
35_2_0073E180 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0074A187 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
35_2_0074A187 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0074A2E4 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
35_2_0074A2E4 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0074A66E FindFirstFileW,Sleep,FindNextFileW,FindClose, |
35_2_0074A66E |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0074686D FindFirstFileW,FindNextFileW,FindClose, |
35_2_0074686D |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0073E9BA GetFileAttributesW,FindFirstFileW,FindClose, |
35_2_0073E9BA |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_007474F0 FindFirstFileW,FindClose, |
35_2_007474F0 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_00747591 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime, |
35_2_00747591 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_0073DE32 GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,FindFirstFileW,DeleteFileW,CompareStringW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
35_2_0073DE32 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_014A3ECD FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, |
35_2_014A3ECD |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_014A17FD GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, |
35_2_014A17FD |
Source: C:\Users\user\AppData\Local\friend\Updater.exe |
Code function: 35_2_014A3FD5 FindFirstFileA,GetLastError, |
35_2_014A3FD5 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CEA187 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
38_2_00CEA187 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CDE180 GetFileAttributesW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
38_2_00CDE180 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CEA2E4 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
38_2_00CEA2E4 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CEA66E FindFirstFileW,Sleep,FindNextFileW,FindClose, |
38_2_00CEA66E |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CE686D FindFirstFileW,FindNextFileW,FindClose, |
38_2_00CE686D |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CDE9BA GetFileAttributesW,FindFirstFileW,FindClose, |
38_2_00CDE9BA |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CE74F0 FindFirstFileW,FindClose, |
38_2_00CE74F0 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CE7591 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime, |
38_2_00CE7591 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_00CDDE32 GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,FindFirstFileW,DeleteFileW,CompareStringW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
38_2_00CDDE32 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_01653765 FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, |
38_2_01653765 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_01651095 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, |
38_2_01651095 |
Source: C:\edgheaa\AutoIt3.exe |
Code function: 38_2_0165386D FindFirstFileA,GetLastError, |
38_2_0165386D |