Click to jump to signature section
Source: uebki.one | Virustotal: Detection: 15% | Perma Link |
Source: https://uebki.one/api/not_working.php?0= | Virustotal: Detection: 9% | Perma Link |
Source: https://uebki.one/api/zapret_readyconfigs.txt | Virustotal: Detection: 12% | Perma Link |
Source: https://uebki.one/api/InfoAboutVPN.php | Virustotal: Detection: 13% | Perma Link |
Source: XWe8H4gRPb.exe, 00000000.00000002.3341182711.0000000002FC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: XWe8H4gRPb.exe, 00000000.00000002.3341182711.0000000002FD6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://uebki.one |
Source: XWe8H4gRPb.exe, 00000000.00000002.3341182711.0000000002FD6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://uebki.oned |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://cdn.uebki.one/Coprer.conf |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://cdn.uebki.one/awg.exe?https://cdn.uebki.one/magic.exeAhttps://cdn.uebki.one/wintun.dll |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://rr1---sn-4g5lznek.googlevideo.com |
Source: XWe8H4gRPb.exe, 00000000.00000002.3343230059.0000000006F3E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://rr1---sn-4g5lznek.googlevideo.com4 |
Source: XWe8H4gRPb.exe, 00000000.00000002.3341182711.0000000002FC1000.00000004.00000800.00020000.00000000.sdmp, XWe8H4gRPb.exe, 00000000.00000002.3341182711.0000000002F51000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://uebki.one |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://uebki.one/ |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://uebki.one/GoodbyeDPIConfigs.exe |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://uebki.one/antizapret/antizapret.zip |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://uebki.one/antizapret/domains-export.txt |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://uebki.one/api/InfoAboutVPN.php |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://uebki.one/api/SendConfigRequest.php?0=0 |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://uebki.one/api/SendConfigRequest.php?0=;. |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://uebki.one/api/gdpi_strateg.txt-_strategyCurlExtraKeys%_strategyExtraKeys |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://uebki.one/api/not_working.php?0= |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://uebki.one/api/zapret_readyconfigs.txt |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://uebki.one/api/zapret_strateg.txt |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://uebki.one/goodbyedpi_configs/ |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://uebki.one/version.txt |
Source: XWe8H4gRPb.exe | String found in binary or memory: https://uebki.one9https://uebki.one/donate.php |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_02DD4E40 | 0_2_02DD4E40 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_02DD9498 | 0_2_02DD9498 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_02DD948B | 0_2_02DD948B |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_07133704 | 0_2_07133704 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_0713AD98 | 0_2_0713AD98 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_07135652 | 0_2_07135652 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_07133454 | 0_2_07133454 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_0713AD8A | 0_2_0713AD8A |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_072DD5F0 | 0_2_072DD5F0 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_072D22C4 | 0_2_072D22C4 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_08952908 | 0_2_08952908 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_08954ED1 | 0_2_08954ED1 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_08951E50 | 0_2_08951E50 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_089528F8 | 0_2_089528F8 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_08951E50 | 0_2_08951E50 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_08954ED1 | 0_2_08954ED1 |
Source: XWe8H4gRPb.exe, 00000000.00000000.2098737315.0000000000CF2000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameGoodbyeDPIConfigs.exe" vs XWe8H4gRPb.exe |
Source: XWe8H4gRPb.exe, 00000000.00000002.3340281508.000000000129E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameclr.dllT vs XWe8H4gRPb.exe |
Source: XWe8H4gRPb.exe | Binary or memory string: OriginalFilenameGoodbyeDPIConfigs.exe" vs XWe8H4gRPb.exe |
Source: unknown | Process created: C:\Users\user\Desktop\XWe8H4gRPb.exe "C:\Users\user\Desktop\XWe8H4gRPb.exe" | |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c sc query "GoodbyeDPI" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\sc.exe sc query "GoodbyeDPI" | |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c sc query "GoodbyeDPI" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\sc.exe sc query "GoodbyeDPI" | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_02DDA281 pushad ; retf | 0_2_02DDA282 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_02DDA25D pushad ; retf | 0_2_02DDA25E |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_02DD0A85 push edi; retf | 0_2_02DD0A82 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_02DD0A6D push edi; retf | 0_2_02DD0A82 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_072C7248 pushfd ; retf | 0_2_072C7255 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Code function: 0_2_089599C0 push eax; retf | 0_2_089599C1 |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -33204139332677172s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -100000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -99859s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -99750s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -99640s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -99531s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -99421s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -99312s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -99203s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -99091s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -98984s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -98875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -98753s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -98625s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -98471s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -98340s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -98207s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -98078s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -97968s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -97859s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -97749s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -97640s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -97531s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -97421s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -97312s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -97203s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -97093s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -96984s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -96874s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -96764s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -96656s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -96546s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -96437s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -96328s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -96218s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -96108s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -95999s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -95890s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -95764s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -95655s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -95546s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -95435s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -95327s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -95218s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -95105s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -94996s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -94889s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -94781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -94668s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe TID: 5176 | Thread sleep time: -94561s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 100000 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 99859 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 99750 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 99640 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 99531 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 99421 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 99312 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 99203 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 99091 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 98984 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 98875 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 98753 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 98625 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 98471 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 98340 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 98207 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 98078 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 97968 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 97859 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 97749 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 97640 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 97531 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 97421 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 97312 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 97203 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 97093 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 96984 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 96874 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 96764 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 96656 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 96546 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 96437 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 96328 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 96218 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 96108 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 95999 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 95890 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 95764 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 95655 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 95546 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 95435 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 95327 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 95218 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 95105 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 94996 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 94889 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 94781 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 94668 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Thread delayed: delay time: 94561 | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Queries volume information: C:\Users\user\Desktop\XWe8H4gRPb.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\XWe8H4gRPb.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |