Source: uebki.one |
Virustotal: Detection: 15% |
Perma Link |
Source: https://uebki.one/api/not_working.php?0= |
Virustotal: Detection: 9% |
Perma Link |
Source: https://uebki.one/api/zapret_readyconfigs.txt |
Virustotal: Detection: 12% |
Perma Link |
Source: https://uebki.one/api/InfoAboutVPN.php |
Virustotal: Detection: 13% |
Perma Link |
Source: XWe8H4gRPb.exe, 00000000.00000002.3341182711.0000000002FC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: XWe8H4gRPb.exe, 00000000.00000002.3341182711.0000000002FD6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://uebki.one |
Source: XWe8H4gRPb.exe, 00000000.00000002.3341182711.0000000002FD6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://uebki.oned |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://cdn.uebki.one/Coprer.conf |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://cdn.uebki.one/awg.exe?https://cdn.uebki.one/magic.exeAhttps://cdn.uebki.one/wintun.dll |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://rr1---sn-4g5lznek.googlevideo.com |
Source: XWe8H4gRPb.exe, 00000000.00000002.3343230059.0000000006F3E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://rr1---sn-4g5lznek.googlevideo.com4 |
Source: XWe8H4gRPb.exe, 00000000.00000002.3341182711.0000000002FC1000.00000004.00000800.00020000.00000000.sdmp, XWe8H4gRPb.exe, 00000000.00000002.3341182711.0000000002F51000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://uebki.one |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://uebki.one/ |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://uebki.one/GoodbyeDPIConfigs.exe |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://uebki.one/antizapret/antizapret.zip |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://uebki.one/antizapret/domains-export.txt |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://uebki.one/api/InfoAboutVPN.php |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://uebki.one/api/SendConfigRequest.php?0=0 |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://uebki.one/api/SendConfigRequest.php?0=;. |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://uebki.one/api/gdpi_strateg.txt-_strategyCurlExtraKeys%_strategyExtraKeys |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://uebki.one/api/not_working.php?0= |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://uebki.one/api/zapret_readyconfigs.txt |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://uebki.one/api/zapret_strateg.txt |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://uebki.one/goodbyedpi_configs/ |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://uebki.one/version.txt |
Source: XWe8H4gRPb.exe |
String found in binary or memory: https://uebki.one9https://uebki.one/donate.php |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_02DD4E40 |
0_2_02DD4E40 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_02DD9498 |
0_2_02DD9498 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_02DD948B |
0_2_02DD948B |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_07133704 |
0_2_07133704 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_0713AD98 |
0_2_0713AD98 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_07135652 |
0_2_07135652 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_07133454 |
0_2_07133454 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_0713AD8A |
0_2_0713AD8A |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_072DD5F0 |
0_2_072DD5F0 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_072D22C4 |
0_2_072D22C4 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_08952908 |
0_2_08952908 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_08954ED1 |
0_2_08954ED1 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_08951E50 |
0_2_08951E50 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_089528F8 |
0_2_089528F8 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_08951E50 |
0_2_08951E50 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_08954ED1 |
0_2_08954ED1 |
Source: XWe8H4gRPb.exe, 00000000.00000000.2098737315.0000000000CF2000.00000002.00000001.01000000.00000003.sdmp |
Binary or memory string: OriginalFilenameGoodbyeDPIConfigs.exe" vs XWe8H4gRPb.exe |
Source: XWe8H4gRPb.exe, 00000000.00000002.3340281508.000000000129E000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameclr.dllT vs XWe8H4gRPb.exe |
Source: XWe8H4gRPb.exe |
Binary or memory string: OriginalFilenameGoodbyeDPIConfigs.exe" vs XWe8H4gRPb.exe |
Source: unknown |
Process created: C:\Users\user\Desktop\XWe8H4gRPb.exe "C:\Users\user\Desktop\XWe8H4gRPb.exe" |
|
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c sc query "GoodbyeDPI" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\sc.exe sc query "GoodbyeDPI" |
|
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c sc query "GoodbyeDPI" |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\sc.exe sc query "GoodbyeDPI" |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Section loaded: dwrite.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_02DDA281 pushad ; retf |
0_2_02DDA282 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_02DDA25D pushad ; retf |
0_2_02DDA25E |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_02DD0A85 push edi; retf |
0_2_02DD0A82 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_02DD0A6D push edi; retf |
0_2_02DD0A82 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_072C7248 pushfd ; retf |
0_2_072C7255 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Code function: 0_2_089599C0 push eax; retf |
0_2_089599C1 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -33204139332677172s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -100000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -99859s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -99750s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -99640s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -99531s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -99421s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -99312s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -99203s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -99091s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -98984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -98875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -98753s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -98625s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -98471s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -98340s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -98207s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -98078s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -97968s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -97859s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -97749s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -97640s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -97531s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -97421s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -97312s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -97203s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -97093s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -96984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -96874s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -96764s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -96656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -96546s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -96437s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -96328s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -96218s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -96108s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -95999s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -95890s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -95764s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -95655s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -95546s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -95435s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -95327s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -95218s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -95105s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -94996s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -94889s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -94781s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -94668s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 |
Thread sleep time: -94561s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 100000 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 99859 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 99750 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 99640 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 99531 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 99421 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 99312 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 99203 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 99091 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 98984 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 98875 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 98753 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 98625 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 98471 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 98340 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 98207 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 98078 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 97968 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 97859 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 97749 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 97640 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 97531 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 97421 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 97312 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 97203 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 97093 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 96984 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 96874 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 96764 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 96656 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 96546 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 96437 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 96328 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 96218 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 96108 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 95999 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 95890 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 95764 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 95655 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 95546 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 95435 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 95327 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 95218 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 95105 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 94996 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 94889 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 94781 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 94668 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Thread delayed: delay time: 94561 |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Queries volume information: C:\Users\user\Desktop\XWe8H4gRPb.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe |
Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation |
Jump to behavior |