Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then shr ecx, 0Dh |
3_2_6CB79DA0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then shr ebp, 0Dh |
3_2_6CB78A50 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov dword ptr [esp], edx |
3_2_6CB6CB60 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov ebp, edi |
3_2_6CB53000 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then shr ecx, 0Dh |
13_2_6CE09DA0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then shr ebp, 0Dh |
13_2_6CE08A50 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov dword ptr [esp], edx |
13_2_6CDFCB60 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov ebp, edi |
13_2_6CDE3000 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then shr ecx, 0Dh |
17_2_6CE09DA0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then shr ebp, 0Dh |
17_2_6CE08A50 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov dword ptr [esp], edx |
17_2_6CDFCB60 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov ebp, edi |
17_2_6CDE3000 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB67DD0 |
3_2_6CB67DD0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB7AD00 |
3_2_6CB7AD00 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB78E10 |
3_2_6CB78E10 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB8CE40 |
3_2_6CB8CE40 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB5BE4F |
3_2_6CB5BE4F |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CBA7FB0 |
3_2_6CBA7FB0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CBC6FB0 |
3_2_6CBC6FB0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB60830 |
3_2_6CB60830 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB65820 |
3_2_6CB65820 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CBC2940 |
3_2_6CBC2940 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB7BAB0 |
3_2_6CB7BAB0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CBD1A00 |
3_2_6CBD1A00 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB7CA70 |
3_2_6CB7CA70 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB5CA60 |
3_2_6CB5CA60 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CBC7490 |
3_2_6CBC7490 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB7C460 |
3_2_6CB7C460 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CBC5590 |
3_2_6CBC5590 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB7D525 |
3_2_6CB7D525 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB7B540 |
3_2_6CB7B540 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB53620 |
3_2_6CB53620 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CBD1640 |
3_2_6CBD1640 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB7A790 |
3_2_6CB7A790 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CBAF732 |
3_2_6CBAF732 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB96730 |
3_2_6CB96730 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CBD3710 |
3_2_6CBD3710 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB73090 |
3_2_6CB73090 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB710D0 |
3_2_6CB710D0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB53000 |
3_2_6CB53000 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB8E040 |
3_2_6CB8E040 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB86040 |
3_2_6CB86040 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB761A0 |
3_2_6CB761A0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB7C100 |
3_2_6CB7C100 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CBC5100 |
3_2_6CBC5100 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CB592E0 |
3_2_6CB592E0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CBC6240 |
3_2_6CBC6240 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CDF7DD0 |
13_2_6CDF7DD0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE0AD00 |
13_2_6CE0AD00 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CDEBE4F |
13_2_6CDEBE4F |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE1CE40 |
13_2_6CE1CE40 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE08E10 |
13_2_6CE08E10 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE37FB0 |
13_2_6CE37FB0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE56FB0 |
13_2_6CE56FB0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CDF0830 |
13_2_6CDF0830 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CDF5820 |
13_2_6CDF5820 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE52940 |
13_2_6CE52940 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE0BAB0 |
13_2_6CE0BAB0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE0CA70 |
13_2_6CE0CA70 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CDECA60 |
13_2_6CDECA60 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE61A00 |
13_2_6CE61A00 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE57490 |
13_2_6CE57490 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE0C460 |
13_2_6CE0C460 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE55590 |
13_2_6CE55590 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE0B540 |
13_2_6CE0B540 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE0D525 |
13_2_6CE0D525 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE61640 |
13_2_6CE61640 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CDE3620 |
13_2_6CDE3620 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE0A790 |
13_2_6CE0A790 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE3F732 |
13_2_6CE3F732 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE26730 |
13_2_6CE26730 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE63710 |
13_2_6CE63710 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE010D0 |
13_2_6CE010D0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE03090 |
13_2_6CE03090 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE1E040 |
13_2_6CE1E040 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE16040 |
13_2_6CE16040 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CDE3000 |
13_2_6CDE3000 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE061A0 |
13_2_6CE061A0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE0C100 |
13_2_6CE0C100 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE55100 |
13_2_6CE55100 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CDE92E0 |
13_2_6CDE92E0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE56240 |
13_2_6CE56240 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CDF7DD0 |
17_2_6CDF7DD0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE0AD00 |
17_2_6CE0AD00 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CDEBE4F |
17_2_6CDEBE4F |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE1CE40 |
17_2_6CE1CE40 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE08E10 |
17_2_6CE08E10 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE37FB0 |
17_2_6CE37FB0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE56FB0 |
17_2_6CE56FB0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CDF0830 |
17_2_6CDF0830 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CDF5820 |
17_2_6CDF5820 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE52940 |
17_2_6CE52940 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE0BAB0 |
17_2_6CE0BAB0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE0CA70 |
17_2_6CE0CA70 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CDECA60 |
17_2_6CDECA60 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE61A00 |
17_2_6CE61A00 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE57490 |
17_2_6CE57490 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE0C460 |
17_2_6CE0C460 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE55590 |
17_2_6CE55590 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE0B540 |
17_2_6CE0B540 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE0D525 |
17_2_6CE0D525 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE61640 |
17_2_6CE61640 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CDE3620 |
17_2_6CDE3620 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE0A790 |
17_2_6CE0A790 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE3F732 |
17_2_6CE3F732 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE26730 |
17_2_6CE26730 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE63710 |
17_2_6CE63710 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE010D0 |
17_2_6CE010D0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE03090 |
17_2_6CE03090 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE1E040 |
17_2_6CE1E040 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE16040 |
17_2_6CE16040 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CDE3000 |
17_2_6CDE3000 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE061A0 |
17_2_6CE061A0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE0C100 |
17_2_6CE0C100 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE55100 |
17_2_6CE55100 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CDE92E0 |
17_2_6CDE92E0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE56240 |
17_2_6CE56240 |
Source: unknown |
Process created: C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll" |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",#1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\LKwQJxGVXf.dll,BarCreate |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",#1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 6564 -s 836 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 4216 -s 812 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\LKwQJxGVXf.dll,BarDestroy |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\LKwQJxGVXf.dll,BarFreeRec |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",BarCreate |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",BarDestroy |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",BarFreeRec |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",_cgo_dummy_export |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 3788 -s 844 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",SpellSpell |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",SpellInit |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",SpellFree |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",SignalInitializeCrashReporting |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",GetInstallDetailsPayload |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",BarRecognize |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",#1 |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\LKwQJxGVXf.dll,BarCreate |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\LKwQJxGVXf.dll,BarDestroy |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\LKwQJxGVXf.dll,BarFreeRec |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",BarCreate |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",BarDestroy |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",BarFreeRec |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",_cgo_dummy_export |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",SpellSpell |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",SpellInit |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",SpellFree |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",SignalInitializeCrashReporting |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",GetInstallDetailsPayload |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",BarRecognize |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",#1 |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CC46FBD push cs; ret |
3_2_6CC46FC5 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CC459F2 push es; iretd |
3_2_6CC45A0F |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CC476AA push ebx; iretd |
3_2_6CC479EB |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4_2_0483B9AB push es; iretd |
4_2_0483B9AE |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4_2_0483AEB4 push ecx; ret |
4_2_0483AED6 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 11_2_04C38FC3 push es; ret |
11_2_04C38FC6 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 11_2_04C38F4F push es; ret |
11_2_04C38F52 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 11_2_04C38F53 push es; ret |
11_2_04C38F4A |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 11_2_04C38F3B push es; ret |
11_2_04C38F4A |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CED6FBD push cs; ret |
13_2_6CED6FC5 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CED59F2 push es; iretd |
13_2_6CED5A0F |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CED76AA push ebx; iretd |
13_2_6CED79EB |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 14_2_04C38FC3 push es; ret |
14_2_04C38FC6 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 14_2_04C3B60B push esi; iretd |
14_2_04C3B982 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 14_2_04C38F4F push es; ret |
14_2_04C38F52 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 14_2_04C3A217 push ds; ret |
14_2_04C3A3B0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 14_2_04C3A3B7 push 0004C303h; ret |
14_2_04C3A58A |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 14_2_04C38F3B push es; ret |
14_2_04C38F4A |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 14_2_04C3A378 push ds; ret |
14_2_04C3A3B0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 15_2_0483A9E2 push edx; ret |
15_2_0483A9E3 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 15_2_0483AEA9 push cs; ret |
15_2_0483AEC7 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CED6FBD push cs; ret |
17_2_6CED6FC5 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CED59F2 push es; iretd |
17_2_6CED5A0F |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CED76AA push ebx; iretd |
17_2_6CED79EB |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 19_2_04C38FC3 push es; ret |
19_2_04C38FC6 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 19_2_04C38FA1 push es; ret |
19_2_04C38FAA |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 19_2_04C3A473 push 0004C303h; ret |
19_2_04C3A58A |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 22_2_04C38FC3 push es; ret |
22_2_04C38FC6 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 22_2_04C38F4F push es; ret |
22_2_04C38F52 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 22_2_04C3A418 pushad ; iretd |
22_2_04C3A419 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 22_2_04C38F3B push es; ret |
22_2_04C38F4A |
Source: C:\Windows\System32\loaddll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: rundll32.exe, 0000000E.00000002.2229264812.0000000002D6A000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllU |
Source: rundll32.exe, 00000013.00000002.2232490236.0000000002ADA000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll6 |
Source: rundll32.exe, 00000018.00000002.2238595309.000000000315A000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll/ |
Source: rundll32.exe, 00000015.00000002.2234698661.000000000064A000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll( |
Source: loaddll32.exe, 00000000.00000002.2237856869.0000000000666000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000003.00000002.2140730643.0000000002B9A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.2139546766.000000000080A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000B.00000002.2166605305.0000000002ACA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.2197069812.00000000033BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000D.00000002.2232731511.00000000033AA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000F.00000002.2230203030.000000000061A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000014.00000002.2233926444.0000000002E0A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000016.00000002.2234749334.0000000002C3A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000017.00000002.2237851825.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CBD4AE0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, |
3_2_6CBD4AE0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6CBD4ADC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, |
3_2_6CBD4ADC |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE64AE0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, |
13_2_6CE64AE0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_6CE64ADC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, |
13_2_6CE64ADC |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE64AE0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, |
17_2_6CE64AE0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 17_2_6CE64ADC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, |
17_2_6CE64ADC |