Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://101.126.19.171:80 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://101.43.160.136:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://107.161.20.142:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://116.202.101.219:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://127.0.0.1:18772/handleOpenWSR?r= |
Source: build.exe, 00000002.00000002.2295681999.0000026B66DAD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://127.0.0.1:18772/handleOpenWSR?r=http://209.38.221.184:8080/get/I85OAzj7Op/yLWFd_user |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://129.151.109.160:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://132.145.17.167:9090 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://147.28.185.29:80 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://159.203.174.113:8090 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://167.235.70.96:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://168.138.211.88:8099 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://18.228.80.130:80 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://185.217.98.121:80 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://185.217.98.121:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://194.164.198.113:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://20.78.55.47:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://206.166.251.4:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://209.38.221.184 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp, build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://209.38.221.184:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://209.38.221.184:8080/%79%4C%57%46%64%5F%66%72%6F%6E%74%64%65%73%6B%40%39%32%37%35%33%37%5F%72% |
Source: build.exe, 00000002.00000002.2295681999.0000026B66B4C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://209.38.221.184:8080/I85OAzj7Op/yLWFd_user |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://209.38.221.184:8080/get |
Source: build.exe, 00000002.00000002.2295681999.0000026B66DAD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://209.38.221.184:8080/get/I85OAzj7Op/yLWFd_user |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://209.38.221.184:8080/yLWFd_user |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://209.38.221.184:8080/yLWFd_user%40927537_report.wsr |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://209.38.221.184:80802 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://38.207.174.88:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://38.60.191.38:80 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66CE0000.00000004.00000800.00020000.00000000.sdmp, build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://41.216.183.9:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66CE0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://41.216.183.9:8080/sendData |
Source: build.exe, 00000002.00000002.2295681999.0000026B66CE0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://41.216.183.9:8080/sendData?pk=MDhCREMyMTRGMDQ3ODIxQUI0NDJDRjRDQ0IzMEMxMUQ=&ta=U29mdHdhcmU=&un |
Source: build.exe, 00000002.00000002.2295681999.0000026B66CE0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://41.216.183.9:80802 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://41.87.207.180:9090 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://46.235.26.83:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://47.96.78.224:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://51.159.4.50:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://65.49.205.24:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://67.230.176.97:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://8.216.92.21:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://8.219.110.16:9999 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://8.222.143.111:8080 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D86000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://api.telegram.org |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://crl.globalsign.com/ca/gstsacasha384g4.crl0 |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0 |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0G |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0c |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://crl.globalsign.com/root-r6.crl0G |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66B4C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com |
Source: build.exe, 00000002.00000002.2295681999.0000026B66B4C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com/line?fields=query |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://ocsp.digicert.com0A |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://ocsp.digicert.com0C |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://ocsp.digicert.com0X |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://ocsp.globalsign.com/ca/gstsacasha384g40C |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://ocsp2.globalsign.com/rootr606 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08 |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gstsacasha384g4.crt0 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.w3.or |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://138.2.92.67:443 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://154.9.207.142:443 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://185.217.98.121:443 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://192.99.196.191:443 |
Source: build.exe, 00000002.00000002.2295681999.0000026B66AC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://5.196.181.135:443 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.tele |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D86000.00000004.00000800.00020000.00000000.sdmp, build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot7722280561:AAEgRsAuRdqeD2qmEUjdhEM6F9R5eAxwIT4/sendMessage |
Source: build.exe, 00000002.00000002.2295681999.0000026B66D06000.00000004.00000800.00020000.00000000.sdmp, build.exe, 00000002.00000002.2295681999.0000026B66D81000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot7722280561:AAEgRsAuRdqeD2qmEUjdhEM6F9R5eAxwIT4/sendMessage?chat_id=77347 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CAE000.00000004.00000800.00020000.00000000.sdmp, build.exe, 00000002.00000002.2301595940.0000026B76CB6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://support.mozilla.org |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CBD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CBD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://support.mozilla.org/products/firefoxgro.allizom.troppus.S3DiLP_FhcLK |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe.0.dr | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76C54000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CAE000.00000004.00000800.00020000.00000000.sdmp, build.exe, 00000002.00000002.2301595940.0000026B76CB6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.mozilla.org |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CBD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.jXqaKJMO4ZEP |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CBD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.NYz0wxyUaYSW |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CBD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/gro.allizom.www.d |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CBD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig |
Source: build.exe, 00000002.00000002.2301595940.0000026B76CBD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.mozilla.org/privacy/firefox/gro.allizom.www. |
Source: unknown | Process created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe" | |
Source: C:\Users\user\Desktop\file.exe | Process created: C:\Users\user\AppData\Local\Temp\build.exe "C:\Users\user\AppData\Local\Temp\build.exe" | |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /c chcp 65001 && netsh wlan show profiles|findstr /R /C:"[ ]:[ ]" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\chcp.com chcp 65001 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\netsh.exe netsh wlan show profiles | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\findstr.exe findstr /R /C:"[ ]:[ ]" | |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /c chcp 65001 && netsh wlan show networks mode=bssid | findstr "SSID BSSID Signal" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\chcp.com chcp 65001 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\netsh.exe netsh wlan show networks mode=bssid | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\findstr.exe findstr "SSID BSSID Signal" | |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /C chcp 65001 && timeout /t 3 > NUL && DEL /F /S /Q /A "C:\Users\user\AppData\Local\Temp\build.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\chcp.com chcp 65001 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\timeout.exe timeout /t 3 | |
Source: C:\Users\user\Desktop\file.exe | Process created: C:\Users\user\AppData\Local\Temp\build.exe "C:\Users\user\AppData\Local\Temp\build.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /c chcp 65001 && netsh wlan show profiles|findstr /R /C:"[ ]:[ ]" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /c chcp 65001 && netsh wlan show networks mode=bssid | findstr "SSID BSSID Signal" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /C chcp 65001 && timeout /t 3 > NUL && DEL /F /S /Q /A "C:\Users\user\AppData\Local\Temp\build.exe" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\chcp.com chcp 65001 | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\netsh.exe netsh wlan show profiles | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\findstr.exe findstr /R /C:"[ ]:[ ]" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\chcp.com chcp 65001 | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\netsh.exe netsh wlan show networks mode=bssid | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\findstr.exe findstr "SSID BSSID Signal" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\chcp.com chcp 65001 | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\timeout.exe timeout /t 3 | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: dlnashext.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: wpdshext.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\chcp.com | Section loaded: ulib.dll | Jump to behavior |
Source: C:\Windows\System32\chcp.com | Section loaded: fsutilext.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: ifmon.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: mprapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: rasmontr.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: mfc42u.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: authfwcfg.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: fwpolicyiomgr.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: firewallapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: fwbase.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: dhcpcmonitor.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: dot3cfg.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: dot3api.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: onex.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: eappcfg.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: eappprxy.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: fwcfg.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: hnetmon.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: netshell.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: netsetupapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: netiohlp.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: nettrace.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: nshhttp.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: httpapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: nshipsec.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: activeds.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: polstore.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: winipsec.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: adsldpc.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: adsldpc.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: nshwfp.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: p2pnetsh.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: p2p.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: rpcnsh.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wcnnetsh.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wlanapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: whhelper.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wlancfg.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wshelper.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wevtapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wwancfg.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wwapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wcmapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: rmclient.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: mobilenetworking.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: peerdistsh.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: ktmw32.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: mprmsg.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\chcp.com | Section loaded: ulib.dll | Jump to behavior |
Source: C:\Windows\System32\chcp.com | Section loaded: fsutilext.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: ifmon.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: mprapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: rasmontr.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: mfc42u.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: authfwcfg.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: fwpolicyiomgr.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: firewallapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: fwbase.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: dhcpcmonitor.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: dot3cfg.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: dot3api.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: onex.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: eappcfg.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: eappprxy.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: fwcfg.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: hnetmon.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: netshell.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: netsetupapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: netiohlp.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: nettrace.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: nshhttp.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: httpapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: nshipsec.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: activeds.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: polstore.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: winipsec.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: adsldpc.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: nshwfp.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: p2pnetsh.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: p2p.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: rpcnsh.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wcnnetsh.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wlanapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: whhelper.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wlancfg.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wshelper.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wevtapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wwancfg.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wwapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wcmapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: rmclient.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: mobilenetworking.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: peerdistsh.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: ktmw32.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: mprmsg.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\chcp.com | Section loaded: ulib.dll | Jump to behavior |
Source: C:\Windows\System32\chcp.com | Section loaded: fsutilext.dll | Jump to behavior |
Source: C:\Windows\System32\timeout.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\netsh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599764 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599656 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599544 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599437 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599328 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599218 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598890 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598672 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598344 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598234 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598125 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598015 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597906 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597797 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597687 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597578 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597469 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597359 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597250 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597141 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597031 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596922 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596812 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596703 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596594 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596484 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596375 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596265 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596155 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596047 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 595937 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 595826 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 595719 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 595609 | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe TID: 4892 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -27670116110564310s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -599875s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -599764s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -599656s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -599544s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -599437s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -599328s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -599218s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -599109s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -599000s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -598890s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -598781s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -598672s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -598562s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -598453s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -598344s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -598234s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -598125s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -598015s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -597906s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -597797s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -597687s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -597578s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -597469s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -597359s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -597250s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -597141s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -597031s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -596922s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -596812s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -596703s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -596594s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -596484s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -596375s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -596265s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -596155s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -596047s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -595937s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -595826s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -595719s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe TID: 7704 | Thread sleep time: -595609s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599764 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599656 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599544 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599437 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599328 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599218 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598890 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598672 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598344 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598234 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598125 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 598015 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597906 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597797 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597687 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597578 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597469 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597359 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597250 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597141 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 597031 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596922 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596812 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596703 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596594 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596484 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596375 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596265 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596155 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 596047 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 595937 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 595826 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 595719 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\build.exe | Thread delayed: delay time: 595609 | Jump to behavior |
Source: file.exe, 00000000.00000002.1238204446.0000000003685000.00000004.00000800.00020000.00000000.sdmp, build.exe, 00000002.00000000.1237262342.0000026B64C32000.00000002.00000001.01000000.00000006.sdmp, build.exe.0.dr | Binary or memory string: qemu' |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - GDCDYNVMware20,11696492231p |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - EU WestVMware20,11696492231n |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Transaction PasswordVMware20,11696492231} |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: interactivebrokers.co.inVMware20,11696492231d |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: netportal.hdfcbank.comVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: outlook.office.comVMware20,11696492231s |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: AMC password management pageVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: interactivebrokers.comVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: microsoft.visualstudio.comVMware20,11696492231x |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - COM.HKVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Change Transaction PasswordVMware20,11696492231^ |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Test URL for global passwords blocklistVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: outlook.office365.comVMware20,11696492231t |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - NDCDYNVMware20,11696492231z |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: discord.comVMware20,11696492231f |
Source: build.exe, 00000002.00000002.2295304015.0000026B66887000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: global block list test formVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: dev.azure.comVMware20,11696492231j |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: www.interactivebrokers.comVMware20,11696492231} |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: www.interactivebrokers.co.inVMware20,11696492231~ |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: bankofamerica.comVMware20,11696492231x |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: trackpan.utiitsl.comVMware20,11696492231h |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: tasks.office.comVMware20,11696492231o |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: account.microsoft.com/profileVMware20,11696492231u |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Change Transaction PasswordVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - EU East & CentralVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: ms.portal.azure.comVMware20,11696492231 |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: turbotax.intuit.comVMware20,11696492231t |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: secure.bankofamerica.comVMware20,11696492231|UE |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Transaction PasswordVMware20,11696492231x |
Source: build.exe, 00000002.00000002.2301595940.0000026B76BAE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - HKVMware20,11696492231] |