Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0073E180 GetFileAttributesW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 35_2_0073E180 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0074A187 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 35_2_0074A187 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0074A2E4 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 35_2_0074A2E4 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0074A66E FindFirstFileW,Sleep,FindNextFileW,FindClose, | 35_2_0074A66E |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0074686D FindFirstFileW,FindNextFileW,FindClose, | 35_2_0074686D |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0073E9BA GetFileAttributesW,FindFirstFileW,FindClose, | 35_2_0073E9BA |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_007474F0 FindFirstFileW,FindClose, | 35_2_007474F0 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_00747591 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime, | 35_2_00747591 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0073DE32 GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,FindFirstFileW,DeleteFileW,CompareStringW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 35_2_0073DE32 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_014A3ECD FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, | 35_2_014A3ECD |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_014A17FD GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 35_2_014A17FD |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_014A3FD5 FindFirstFileA,GetLastError, | 35_2_014A3FD5 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CEA187 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 38_2_00CEA187 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CDE180 GetFileAttributesW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 38_2_00CDE180 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CEA2E4 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 38_2_00CEA2E4 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CEA66E FindFirstFileW,Sleep,FindNextFileW,FindClose, | 38_2_00CEA66E |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CE686D FindFirstFileW,FindNextFileW,FindClose, | 38_2_00CE686D |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CDE9BA GetFileAttributesW,FindFirstFileW,FindClose, | 38_2_00CDE9BA |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CE74F0 FindFirstFileW,FindClose, | 38_2_00CE74F0 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CE7591 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime, | 38_2_00CE7591 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CDDE32 GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,FindFirstFileW,DeleteFileW,CompareStringW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 38_2_00CDDE32 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_01653765 FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, | 38_2_01653765 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_01651095 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 38_2_01651095 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_0165386D FindFirstFileA,GetLastError, | 38_2_0165386D |
Source: MSBuild.exe, 00000025.00000002.2940433393.0000000001459000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://152.89.198.124/8bdDsv3dk2FF/index.php |
Source: MSBuild.exe, 00000025.00000002.2940433393.0000000001418000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://152.89.198.124/8bdDsv3dk2FF/index.phped |
Source: MSBuild.exe, 00000025.00000002.2940433393.0000000001447000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://152.89.198.124/8bdDsv3dk2FF/index.phpp |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl.certum.pl/cscasha2.crl0q |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl.certum.pl/ctnca.crl0k |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0 |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0 |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0c |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r3.crl0 |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0# |
Source: Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://cscasha2.ocsp-ce |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://cscasha2.ocsp-certum.com04 |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.sectigo.com0 |
Source: Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.us |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ocsp2.globalsign.com/gstimestampingsha2g20 |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://repository.certum |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://repository.certum.pl/cscasha2.cer0 |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://repository.certum.pl/ctnca.cer09 |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08 |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0 |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://subca.ocsp-certum.com01 |
Source: Updater.exe, 0000001C.00000000.1722434360.00000000007A5000.00000002.00000001.01000000.0000000B.sdmp, Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2237879477.00000000007A5000.00000002.00000001.01000000.0000000B.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000000.2362895220.0000000000D45000.00000002.00000001.01000000.0000000D.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://www.autoitscript.com/autoit3/X |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://www.certum.pl/CPS0 |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://jrsoftware.org/ |
Source: Reminder.exe, 00000000.00000000.1678698708.0000000000861000.00000020.00000001.01000000.00000003.sdmp | String found in binary or memory: https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://jrsoftware.org0 |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://sectigo.com/CPS0D |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.autoitscript.com/autoit3/ |
Source: Reminder.tmp, 00000001.00000003.1684312693.00000000037D0000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000003.1686108256.0000000002630000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000003.00000003.1726794198.0000000003170000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.certum.pl/CPS0 |
Source: AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: Updater.exe, 00000023.00000003.2236424027.0000000004B3F000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000002.2240225926.000000000496D000.00000004.00001000.00020000.00000000.sdmp, Updater.exe, 00000023.00000003.2236568857.0000000004A53000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407053379.0000000004D8F000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000002.2411997935.0000000004BBD000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 00000026.00000003.2407350277.0000000004CA3000.00000004.00001000.00020000.00000000.sdmp, AutoIt3.exe, 0000002A.00000003.2497030014.0000000004B43000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.globalsign.com/repository/06 |
Source: Reminder.exe, 00000000.00000003.1680434117.0000000002F70000.00000004.00001000.00020000.00000000.sdmp, Reminder.exe, 00000000.00000003.1680920376.000000007F2BB000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000000.1682457089.0000000000A41000.00000020.00000001.01000000.00000004.sdmp, Reminder.tmp, 00000003.00000000.1688593494.0000000000F1D000.00000020.00000001.01000000.00000009.sdmp | String found in binary or memory: https://www.innosetup.com/ |
Source: Reminder.exe, 00000000.00000003.1680434117.0000000002F70000.00000004.00001000.00020000.00000000.sdmp, Reminder.exe, 00000000.00000003.1680920376.000000007F2BB000.00000004.00001000.00020000.00000000.sdmp, Reminder.tmp, 00000001.00000000.1682457089.0000000000A41000.00000020.00000001.01000000.00000004.sdmp, Reminder.tmp, 00000003.00000000.1688593494.0000000000F1D000.00000020.00000001.01000000.00000009.sdmp | String found in binary or memory: https://www.remobjects.com/ps |
Source: unknown | Network traffic detected: HTTP traffic on port 57886 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57943 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57725 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57989 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57966 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57805 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57748 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57931 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57908 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57977 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57851 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57794 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57816 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57759 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57919 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57840 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57875 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57714 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57932 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57827 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57852 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57772 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57885 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57990 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57897 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57954 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57874 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57863 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57965 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57804 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57747 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57896 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57873 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57712 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57850 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57829 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57735 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57758 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57838 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57784 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57910 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57956 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57773 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57921 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57967 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57724 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57988 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57806 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57861 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57955 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57978 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57762 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57817 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57922 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57746 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57895 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57933 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57828 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57757 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57796 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57884 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57944 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57839 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57785 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57905 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57848 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57928 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57825 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57797 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57940 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57774 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57860 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57883 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57872 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57763 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57952 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57734 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57837 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57745 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57802 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57871 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57894 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57974 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57733 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57756 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57798 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57939 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57813 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57987 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57786 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57906 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57849 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57962 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57775 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57917 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57722 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57951 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57764 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57787 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57930 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57953 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57976 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57918 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57815 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57721 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57985 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57744 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57847 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57929 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57826 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57755 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57776 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57882 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57858 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57942 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57907 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57720 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57997 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57859 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57941 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57881 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57964 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57836 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57803 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57765 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57788 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57870 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57975 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57732 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57799 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57814 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57986 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57743 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57809 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57806 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57927 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57805 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57926 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57929 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57807 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57928 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57802 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57923 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57801 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57922 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57804 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57925 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57803 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57924 |
Source: unknown | Network traffic detected: HTTP traffic on port 57754 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57777 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57800 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57921 |
Source: unknown | Network traffic detected: HTTP traffic on port 57811 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57857 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57834 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57937 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57914 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49675 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57822 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57742 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57817 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57938 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57816 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57937 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57819 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57818 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57939 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57813 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57934 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57812 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57933 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57815 |
Source: unknown | Network traffic detected: HTTP traffic on port 57960 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57814 |
Source: unknown | Network traffic detected: HTTP traffic on port 57925 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57935 |
Source: unknown | Network traffic detected: HTTP traffic on port 57868 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57930 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57811 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57932 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57810 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57931 |
Source: unknown | Network traffic detected: HTTP traffic on port 57731 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57995 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57892 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57766 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57789 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57869 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57828 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57949 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57827 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57948 |
Source: unknown | Network traffic detected: HTTP traffic on port 57959 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57984 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57829 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57945 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57823 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57944 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57826 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57825 |
Source: unknown | Network traffic detected: HTTP traffic on port 57926 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57946 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57820 |
Source: unknown | Network traffic detected: HTTP traffic on port 57903 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57941 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57940 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57822 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57943 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57821 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57942 |
Source: unknown | Network traffic detected: HTTP traffic on port 57753 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57950 |
Source: unknown | Network traffic detected: HTTP traffic on port 57730 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57971 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57891 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57718 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57839 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57717 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57838 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57959 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57719 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57714 |
Source: unknown | Network traffic detected: HTTP traffic on port 57948 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57956 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57834 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57955 |
Source: unknown | Network traffic detected: HTTP traffic on port 57719 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57716 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57837 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57958 |
Source: unknown | Network traffic detected: HTTP traffic on port 57996 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57715 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57836 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57957 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57831 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57952 |
Source: unknown | Network traffic detected: HTTP traffic on port 57778 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57830 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57951 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57712 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57833 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57954 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57832 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57953 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57840 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57961 |
Source: unknown | Network traffic detected: HTTP traffic on port 57810 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57960 |
Source: unknown | Network traffic detected: HTTP traffic on port 57880 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57741 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57844 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57982 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57867 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57973 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57950 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57729 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57717 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57801 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57790 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57904 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57752 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57812 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57833 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57915 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57879 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57823 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57908 |
Source: unknown | Network traffic detected: HTTP traffic on port 57800 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57905 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57904 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57907 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57906 |
Source: unknown | Network traffic detected: HTTP traffic on port 57949 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57901 |
Source: unknown | Network traffic detected: HTTP traffic on port 57961 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57900 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57903 |
Source: unknown | Network traffic detected: HTTP traffic on port 57718 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57902 |
Source: unknown | Network traffic detected: HTTP traffic on port 57779 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57791 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57916 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57740 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57919 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57916 |
Source: unknown | Network traffic detected: HTTP traffic on port 57927 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57915 |
Source: unknown | Network traffic detected: HTTP traffic on port 57845 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57918 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57917 |
Source: unknown | Network traffic detected: HTTP traffic on port 57983 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57912 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57911 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57914 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57913 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57910 |
Source: unknown | Network traffic detected: HTTP traffic on port 57856 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57938 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57972 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57890 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57768 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57739 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57716 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57819 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57957 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57769 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57768 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57889 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57765 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57886 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57764 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57885 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57888 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57766 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57887 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57772 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57771 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57892 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57774 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57895 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57773 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57894 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57770 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57891 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57890 |
Source: unknown | Network traffic detected: HTTP traffic on port 57992 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57780 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57981 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57843 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57889 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57900 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57779 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57776 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57897 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57775 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57896 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57778 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57899 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57777 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57898 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57782 |
Source: unknown | Network traffic detected: HTTP traffic on port 57728 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57785 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57784 |
Source: unknown | Network traffic detected: HTTP traffic on port 57946 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57781 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57780 |
Source: unknown | Network traffic detected: HTTP traffic on port 57854 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57911 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57787 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57786 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57789 |
Source: unknown | Network traffic detected: HTTP traffic on port 57888 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57788 |
Source: unknown | Network traffic detected: HTTP traffic on port 57727 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57794 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57793 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57796 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57790 |
Source: unknown | Network traffic detected: HTTP traffic on port 57807 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57832 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57855 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57945 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57792 |
Source: unknown | Network traffic detected: HTTP traffic on port 57968 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57791 |
Source: unknown | Network traffic detected: HTTP traffic on port 57769 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57912 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57818 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57923 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57866 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57798 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57797 |
Source: unknown | Network traffic detected: HTTP traffic on port 57792 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57799 |
Source: unknown | Network traffic detected: HTTP traffic on port 57750 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57993 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57877 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57934 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57781 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57821 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57729 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57728 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57849 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57725 |
Source: unknown | Network traffic detected: HTTP traffic on port 57770 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57924 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57967 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57724 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57845 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57966 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57727 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57848 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57969 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57726 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57847 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57968 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57721 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57842 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57720 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57841 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57962 |
Source: unknown | Network traffic detected: HTTP traffic on port 57793 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57844 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57965 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57722 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57843 |
Source: unknown | Network traffic detected: HTTP traffic on port 57901 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57964 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57970 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57730 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57851 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57972 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57850 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57971 |
Source: unknown | Network traffic detected: HTTP traffic on port 57809 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57841 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57853 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57876 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57761 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57899 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57738 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57739 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57857 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57978 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57735 |
Source: unknown | Network traffic detected: HTTP traffic on port 57830 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57856 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57977 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57738 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57859 |
Source: unknown | Network traffic detected: HTTP traffic on port 57864 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57737 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57858 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57732 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57853 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57974 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57731 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57852 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57973 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57734 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57855 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57976 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57733 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57854 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57975 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57860 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57981 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57980 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57741 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57983 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57740 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57861 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57982 |
Source: unknown | Network traffic detected: HTTP traffic on port 57970 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57991 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57749 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57980 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57737 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57842 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57747 |
Source: unknown | Network traffic detected: HTTP traffic on port 57865 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57868 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57989 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57746 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57867 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57988 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57749 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57748 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57869 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57743 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57864 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57985 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57742 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57863 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57984 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57745 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57866 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57987 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57744 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57865 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57986 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57750 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57871 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57992 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57870 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57991 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57752 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57873 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57872 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57993 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57990 |
Source: unknown | Network traffic detected: HTTP traffic on port 57782 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57935 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57715 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57820 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 57958 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57758 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 57879 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006D7070 | 35_2_006D7070 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006E3AD9 | 35_2_006E3AD9 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0070E32F | 35_2_0070E32F |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006F24CA | 35_2_006F24CA |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_00706599 | 35_2_00706599 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0075C844 | 35_2_0075C844 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006F29E3 | 35_2_006F29E3 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006FC9C0 | 35_2_006FC9C0 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006ECBF0 | 35_2_006ECBF0 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_00706C09 | 35_2_00706C09 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_00742D81 | 35_2_00742D81 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006DCE20 | 35_2_006DCE20 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006DEE00 | 35_2_006DEE00 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006F2F23 | 35_2_006F2F23 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006EF0DA | 35_2_006EF0DA |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_00739168 | 35_2_00739168 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0076525A | 35_2_0076525A |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006ED37F | 35_2_006ED37F |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006F7746 | 35_2_006F7746 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006F1964 | 35_2_006F1964 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006F7975 | 35_2_006F7975 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006F7BD2 | 35_2_006F7BD2 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006DDC70 | 35_2_006DDC70 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_00709D1E | 35_2_00709D1E |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_006F1FC1 | 35_2_006F1FC1 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_014B89A9 | 35_2_014B89A9 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_014B89A2 | 35_2_014B89A2 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C77070 | 38_2_00C77070 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C83AD9 | 38_2_00C83AD9 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CAE32F | 38_2_00CAE32F |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C924CA | 38_2_00C924CA |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CA6599 | 38_2_00CA6599 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CFC844 | 38_2_00CFC844 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C9C9C0 | 38_2_00C9C9C0 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C929E3 | 38_2_00C929E3 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C8CBF0 | 38_2_00C8CBF0 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CA6C09 | 38_2_00CA6C09 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CE2D81 | 38_2_00CE2D81 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C7EE00 | 38_2_00C7EE00 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C7CE20 | 38_2_00C7CE20 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C92F23 | 38_2_00C92F23 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C8F0DA | 38_2_00C8F0DA |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CD9168 | 38_2_00CD9168 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00D0525A | 38_2_00D0525A |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C8D37F | 38_2_00C8D37F |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C97746 | 38_2_00C97746 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C91964 | 38_2_00C91964 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C97975 | 38_2_00C97975 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C97BD2 | 38_2_00C97BD2 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C7DC70 | 38_2_00C7DC70 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CA9D1E | 38_2_00CA9D1E |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00C91FC1 | 38_2_00C91FC1 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_01668241 | 38_2_01668241 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_0166823A | 38_2_0166823A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_0040B650 | 41_2_0040B650 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_004051D0 | 41_2_004051D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_004531E2 | 41_2_004531E2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_0044623A | 41_2_0044623A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_0042E2C5 | 41_2_0042E2C5 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_004312A3 | 41_2_004312A3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_0045C476 | 41_2_0045C476 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_004064C0 | 41_2_004064C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_00405480 | 41_2_00405480 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_0045C596 | 41_2_0045C596 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_00433644 | 41_2_00433644 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_00405730 | 41_2_00405730 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_00449780 | 41_2_00449780 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_00453969 | 41_2_00453969 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_0045A9D8 | 41_2_0045A9D8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_0042EAB4 | 41_2_0042EAB4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_00441C90 | 41_2_00441C90 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 41_2_00441D3D | 41_2_00441D3D |
Source: unknown | Process created: C:\Users\user\Desktop\Reminder.exe "C:\Users\user\Desktop\Reminder.exe" | |
Source: C:\Users\user\Desktop\Reminder.exe | Process created: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp "C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp" /SL5="$20434,1768989,845824,C:\Users\user\Desktop\Reminder.exe" | |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Process created: C:\Users\user\Desktop\Reminder.exe "C:\Users\user\Desktop\Reminder.exe" /VERYSILENT | |
Source: C:\Users\user\Desktop\Reminder.exe | Process created: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp "C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp" /SL5="$20442,1768989,845824,C:\Users\user\Desktop\Reminder.exe" /VERYSILENT | |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq wrsa.exe" /FO CSV /NH | find /I "wrsa.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq wrsa.exe" /FO CSV /NH | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "wrsa.exe" | |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq opssvc.exe" /FO CSV /NH | find /I "opssvc.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq opssvc.exe" /FO CSV /NH | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "opssvc.exe" | |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq avastui.exe" /FO CSV /NH | find /I "avastui.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq avastui.exe" /FO CSV /NH | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "avastui.exe" | |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq avgui.exe" /FO CSV /NH | find /I "avgui.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq avgui.exe" /FO CSV /NH | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "avgui.exe" | |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq nswscsvc.exe" /FO CSV /NH | find /I "nswscsvc.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq nswscsvc.exe" /FO CSV /NH | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "nswscsvc.exe" | |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq sophoshealth.exe" /FO CSV /NH | find /I "sophoshealth.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq sophoshealth.exe" /FO CSV /NH | |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Process created: C:\Users\user\AppData\Local\friend\Updater.exe "C:\Users\user\AppData\Local\friend\\Updater.exe" "C:\Users\user\AppData\Local\friend\\yeorling.csv" | |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c ping -n 5 127.0.0.1 >nul && updater.exe C:\ProgramData\\huv9LF4.a3x && del C:\ProgramData\\huv9LF4.a3x | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\PING.EXE ping -n 5 127.0.0.1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\friend\Updater.exe updater.exe C:\ProgramData\\huv9LF4.a3x | |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | |
Source: unknown | Process created: C:\edgheaa\AutoIt3.exe "C:\edgheaa\AutoIt3.exe" C:\edgheaa\fkccfcd.a3x | |
Source: C:\edgheaa\AutoIt3.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | |
Source: C:\edgheaa\AutoIt3.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | |
Source: C:\edgheaa\AutoIt3.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | |
Source: unknown | Process created: C:\edgheaa\AutoIt3.exe "C:\edgheaa\AutoIt3.exe" C:\edgheaa\fkccfcd.a3x | |
Source: C:\edgheaa\AutoIt3.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | |
Source: C:\edgheaa\AutoIt3.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | |
Source: C:\Users\user\Desktop\Reminder.exe | Process created: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp "C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp" /SL5="$20434,1768989,845824,C:\Users\user\Desktop\Reminder.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Process created: C:\Users\user\Desktop\Reminder.exe "C:\Users\user\Desktop\Reminder.exe" /VERYSILENT | Jump to behavior |
Source: C:\Users\user\Desktop\Reminder.exe | Process created: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp "C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp" /SL5="$20442,1768989,845824,C:\Users\user\Desktop\Reminder.exe" /VERYSILENT | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq wrsa.exe" /FO CSV /NH | find /I "wrsa.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq opssvc.exe" /FO CSV /NH | find /I "opssvc.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq avastui.exe" /FO CSV /NH | find /I "avastui.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq avgui.exe" /FO CSV /NH | find /I "avgui.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq nswscsvc.exe" /FO CSV /NH | find /I "nswscsvc.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq sophoshealth.exe" /FO CSV /NH | find /I "sophoshealth.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Process created: C:\Users\user\AppData\Local\friend\Updater.exe "C:\Users\user\AppData\Local\friend\\Updater.exe" "C:\Users\user\AppData\Local\friend\\yeorling.csv" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq wrsa.exe" /FO CSV /NH | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "wrsa.exe" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq opssvc.exe" /FO CSV /NH | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "opssvc.exe" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq avastui.exe" /FO CSV /NH | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "avastui.exe" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq avgui.exe" /FO CSV /NH | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "avgui.exe" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq nswscsvc.exe" /FO CSV /NH | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "nswscsvc.exe" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq sophoshealth.exe" /FO CSV /NH | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "sophoshealth.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c ping -n 5 127.0.0.1 >nul && updater.exe C:\ProgramData\\huv9LF4.a3x && del C:\ProgramData\\huv9LF4.a3x | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\PING.EXE ping -n 5 127.0.0.1 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\friend\Updater.exe updater.exe C:\ProgramData\\huv9LF4.a3x | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Reminder.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Reminder.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B7H8V.tmp\Reminder.tmp | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Reminder.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Reminder.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: explorerframe.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-NL1P1.tmp\Reminder.tmp | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\find.exe | Section loaded: ulib.dll | Jump to behavior |
Source: C:\Windows\System32\find.exe | Section loaded: fsutilext.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\find.exe | Section loaded: ulib.dll | Jump to behavior |
Source: C:\Windows\System32\find.exe | Section loaded: fsutilext.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\find.exe | Section loaded: ulib.dll | Jump to behavior |
Source: C:\Windows\System32\find.exe | Section loaded: fsutilext.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\find.exe | Section loaded: ulib.dll | Jump to behavior |
Source: C:\Windows\System32\find.exe | Section loaded: fsutilext.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\find.exe | Section loaded: ulib.dll | Jump to behavior |
Source: C:\Windows\System32\find.exe | Section loaded: fsutilext.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\find.exe | Section loaded: ulib.dll | Jump to behavior |
Source: C:\Windows\System32\find.exe | Section loaded: fsutilext.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\edgheaa\AutoIt3.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0073E180 GetFileAttributesW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 35_2_0073E180 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0074A187 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 35_2_0074A187 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0074A2E4 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 35_2_0074A2E4 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0074A66E FindFirstFileW,Sleep,FindNextFileW,FindClose, | 35_2_0074A66E |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0074686D FindFirstFileW,FindNextFileW,FindClose, | 35_2_0074686D |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0073E9BA GetFileAttributesW,FindFirstFileW,FindClose, | 35_2_0073E9BA |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_007474F0 FindFirstFileW,FindClose, | 35_2_007474F0 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_00747591 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime, | 35_2_00747591 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_0073DE32 GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,FindFirstFileW,DeleteFileW,CompareStringW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 35_2_0073DE32 |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_014A3ECD FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, | 35_2_014A3ECD |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_014A17FD GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 35_2_014A17FD |
Source: C:\Users\user\AppData\Local\friend\Updater.exe | Code function: 35_2_014A3FD5 FindFirstFileA,GetLastError, | 35_2_014A3FD5 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CEA187 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 38_2_00CEA187 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CDE180 GetFileAttributesW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 38_2_00CDE180 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CEA2E4 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 38_2_00CEA2E4 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CEA66E FindFirstFileW,Sleep,FindNextFileW,FindClose, | 38_2_00CEA66E |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CE686D FindFirstFileW,FindNextFileW,FindClose, | 38_2_00CE686D |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CDE9BA GetFileAttributesW,FindFirstFileW,FindClose, | 38_2_00CDE9BA |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CE74F0 FindFirstFileW,FindClose, | 38_2_00CE74F0 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CE7591 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime, | 38_2_00CE7591 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_00CDDE32 GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,FindFirstFileW,DeleteFileW,CompareStringW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 38_2_00CDDE32 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_01653765 FindFirstFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, | 38_2_01653765 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_01651095 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn, | 38_2_01651095 |
Source: C:\edgheaa\AutoIt3.exe | Code function: 38_2_0165386D FindFirstFileA,GetLastError, | 38_2_0165386D |