Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://45.137.22.126:5 |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FF1000.00000004.00000800.00020000.00000000.sdmp, 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://45.137.22.126:55615 |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://45.137.22.126:55615/ |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FF1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://45.137.22.126:55615t-fq |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FF1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.datacontract.org/2004/07/ |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/soap/actor/next |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FB0000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/faultX |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FB0000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/ |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/0 |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Endpoint/CheckConnect |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Endpoint/CheckConnectResponse |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Endpoint/EnvironmentSettings |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Endpoint/EnvironmentSettingsResponse |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FF1000.00000004.00000800.00020000.00000000.sdmp, 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp, 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FD7000.00000004.00000800.00020000.00000000.sdmp, 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FB0000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Endpoint/GetUpdates |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Endpoint/GetUpdatesResponse |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Endpoint/SetEnviron |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Endpoint/SetEnvironment |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Endpoint/SetEnvironmentResponse |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Endpoint/VerifyUpdate |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Endpoint/VerifyUpdateResponse |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.carterandcone.coml |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers/? |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers/frere-user.html |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers8 |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers? |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designersG |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fonts.com |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.founder.com.cn/cn |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.founder.com.cn/cn/bThe |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.founder.com.cn/cn/cThe |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.galapagosdesign.com/DPlease |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.goodfont.co.kr |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.jiyu-kobo.co.jp/ |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.sajatypeworks.com |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742706998.0000000006474000.00000004.00000020.00020000.00000000.sdmp, 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.sakkal.com |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.sandoll.co.kr |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.tiro.com |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.typography.netD |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.urwpp.deDPlease |
Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.zhongyicts.com.cn |
Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.dr |
String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FB0000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.ip.sb |
Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FB0000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.ip.sb/geoip |
Source: 9dOKGgFNL2.exe, 9dOKGgFNL2.exe, 00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: https://api.ip.sb/geoip%USERPEnvironmentROFILE% |
Source: 9dOKGgFNL2.exe, 9dOKGgFNL2.exe, 00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: https://api.ipify.orgcookies//settinString.Removeg |
Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.dr |
String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.dr |
String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.dr |
String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.dr |
String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.dr |
String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.dr |
String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: 9dOKGgFNL2.exe, 9dOKGgFNL2.exe, 00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io/ip%appdata% |
Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.dr |
String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.dr |
String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: 2.2.9dOKGgFNL2.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: 2.2.9dOKGgFNL2.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 0.2.9dOKGgFNL2.exe.458a6f0.2.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: 0.2.9dOKGgFNL2.exe.458a6f0.2.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 0.2.9dOKGgFNL2.exe.45a2510.1.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: 0.2.9dOKGgFNL2.exe.45a2510.1.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 0.2.9dOKGgFNL2.exe.45a2510.1.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: 0.2.9dOKGgFNL2.exe.45a2510.1.raw.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 0.2.9dOKGgFNL2.exe.458a6f0.2.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: 0.2.9dOKGgFNL2.exe.458a6f0.2.raw.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: 00000000.00000002.1741382956.0000000004491000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: 00000000.00000002.1741382956.000000000458A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: Process Memory Space: 9dOKGgFNL2.exe PID: 7536, type: MEMORYSTR |
Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: Process Memory Space: 9dOKGgFNL2.exe PID: 7712, type: MEMORYSTR |
Matched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23 |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: dwrite.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: iconcodecservice.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, RI5CbnHZJMOX38NIWe.cs |
High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'Jja8bB6lEU', 'NpG8WY4SLZ', 'i5g8z9xtJM', 'llbGpIplh1', 's9gGkAL39b', 'zgOG8XliWj', 'gRYGG5q8Fv', 'OWoDag98XMVVT6ETqbp' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, TVYCZS8CsAAf6xRfPr.cs |
High entropy of concatenated method names: 'abTMGse3k', 'FfQD8fGjE', 'ocWX9F3Qj', 'o7EEysSd2', 'I7yu3gEtP', 'Ye1BG8lwQ', 'I34Ti0u4RcG9Qa7hdb', 'c0F1wry08HThRQ3JtF', 'woQY4oQUq', 'YwOoaVpYZ' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, mT0lgMk0UGmjhglQpy2.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'oNRRJJjkvv', 'CjuRoHlLyi', 'lHLR5jNOxN', 'aT3RRnSxHv', 'e7xRdkc7fx', 'xhKRsaPn3I', 'gVNR2Pxsy6' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, KXppZwBPgJ7E76VbXs.cs |
High entropy of concatenated method names: 'cuulhrjjTF', 'A6alEaKRRv', 'XDDHgVl8Pd', 'PkjHFw6B1X', 'nSdHcJfTXo', 'OoJHL1JuHO', 'SeDHvKtLK0', 'fapHx59X52', 'r99HTYZJSi', 'fJcHCe16Rq' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, nlmoTBWi5RrBNjduPP.cs |
High entropy of concatenated method names: 'v3UoH7e74r', 'r5ColW5onc', 'QEcotKLZDq', 'E6noIJVudW', 'cjyoJEWJf6', 'yCWoKUh9fA', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, T5CUBJkkW6oTYTPm6hD.cs |
High entropy of concatenated method names: 'utQoWGyfoQ', 'EBXozPAXTS', 'vCk5pjR2wW', 'qsf5ktLSs9', 'f2k58Y4chO', 'HvI5G57mZ0', 'I9X50wT2Z7', 'rjT53EdlhF', 'OjE5yVTrP7', 'YmP5q5xPxi' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, qDbtOObWgkLUDUcOmK.cs |
High entropy of concatenated method names: 'cunJ6k4HuC', 'RtjJUh4WPV', 'OldJgCnBv1', 'F1YJFAfh04', 'ArwJcubO61', 'ye1JLGOyeY', 's69JvqD3yP', 'OstJxSfJAf', 'L6VJTTx7vZ', 'FJMJC6wGqb' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, Tgldtnuspxe3w9nTJA.cs |
High entropy of concatenated method names: 'M9wHDRHrdU', 'lPpHXPKqoQ', 'VDPHZGtRXK', 'Xb6HuwNOpL', 'kuGHPAmcBH', 'vpIHSc0G6B', 'p4sHVwZLO6', 'rxtHY6Tmrv', 'CbBHJaf2CW', 'KHRHo7QA90' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, pa30ECvIFvyAltBGSh.cs |
High entropy of concatenated method names: 'tBDIyO21fN', 'iE8IHYIm0a', 'hw3ItxSF45', 'B1rtWHGog3', 'KIItzWhFfb', 'j2sIpCAW4U', 'HVsIkyN3DW', 'UqbI80l6MO', 'FU1IGsgEUS', 'IO9I0U0D91' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, to6tbw1Sv4LCFDGbFJ.cs |
High entropy of concatenated method names: 'KJZ7ZJJeLY', 'l8D7u7wv5m', 'TuI76cIJeD', 'y317UNlsQn', 'LNU7FTlA4i', 'x187ceYm7b', 'del7v1ZEX9', 'pyn7xTJ7u1', 'r0k7CLxjj7', 'OUQ7ja5j8L' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, neicNOfGWVJmDBuMMa.cs |
High entropy of concatenated method names: 'DikVmP2p2L', 'PeIVW2r6qk', 'JYYYpHBxAr', 'qKmYkZRh9D', 'MY3VjXuh8G', 'R89VNoYK3i', 'eXtV1fpGv4', 'KrpV4JsD35', 'lHKVA3upPb', 'AJxViniaRr' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, Rc2muXTKqVZvJsmYO7.cs |
High entropy of concatenated method names: 'cfIIeo0CNR', 'JmhIOHRY7q', 'eh0IMm9UBh', 'nDkIDJR07p', 'qoxIhLi5oB', 'i2oIXM3EfE', 'XQHIEVrjOW', 'ySLIZSAb7Y', 'QxjIu9oM3E', 'lEvIB0OCXs' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, TLjf954KTOhdvwbmoK.cs |
High entropy of concatenated method names: 'TN6PCUfeNQ', 'UIjPNB2QMf', 'IubP4pjyUb', 'xFBPADHqnK', 'twkPUQLnkX', 'wQVPgP0Iet', 'Hr2PFDLgXT', 'yQ6PcVARZE', 'TLRPLLHUji', 'hMMPvfiAEj' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, demNsXKQQ5dOWKyKaT.cs |
High entropy of concatenated method names: 'K0EG3hIdYk', 'nZqGy7xs3s', 'lyyGqyJu0d', 'zCcGHbB18s', 'mOMGlFWd1D', 'c7aGtdJoPg', 'hE8GIADHYc', 'jIHGKFEn6e', 'aUsGnvT6Y0', 'oWxGQvwnQy' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, O23pNJ6EhjttsNQhGK.cs |
High entropy of concatenated method names: 'VqYt3uxTLn', 'FRQtqg3KDy', 'H6rtl4LRLm', 'GRgtIocc4x', 'eXYtKXqBnb', 'LjtlwUL1qE', 'vA7lf8XP7U', 'AN8l9viaIk', 'Ee9lmjH2qK', 'vXMlb9qiZb' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, d5oNk0qNHVBJ02cV5H.cs |
High entropy of concatenated method names: 'Dispose', 'dKNkbKj2BC', 'N6F8U9nZPW', 'xt8nNCcuZx', 'WaPkWj1CsY', 'lAGkzIRUAJ', 'ProcessDialogKey', 'duV8pDbtOO', 'Ygk8kLUDUc', 'ymK887lmoT' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, GnKswFzT5fBSNjTCYX.cs |
High entropy of concatenated method names: 'guZoXFdbJD', 'zaGoZj1VEJ', 'TkxouXkZK9', 'UqKo660TxR', 'dj6oUNCV5S', 'lUdoFCiJwd', 'aEUockj3NL', 'BbSo2DlJTs', 'jjuoeHRPNO', 'JHFoOqssRx' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, anJOVC9Gs0KNKj2BCm.cs |
High entropy of concatenated method names: 'nLBJPSNxIK', 'MX0JV8rTGU', 'zXgJJSJDia', 'hZdJ5VUsh9', 'cQnJdRxPDQ', 'AaZJ2akfLy', 'Dispose', 'qpOYy6aJAf', 'CPxYqCafiQ', 'C9lYHy4aBY' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, iZq82EZ6VPakI888Ti.cs |
High entropy of concatenated method names: 'ETaq4qXUTJ', 'XKJqAsVrDR', 'T8CqiVQ8GZ', 'WFkqr0rMWw', 'kdyqwQf4v5', 'i8tqfUDUg5', 'rgWq93sdG4', 'N7MqmNm0Gq', 'itEqbXKUMv', 'FIWqW9FIZ6' |
Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, QjRGfp0mhEGSXg3p4e.cs |
High entropy of concatenated method names: 'GmtkIZq82E', 'GVPkKakI88', 'lspkQxe3w9', 'lTJkaALXpp', 'GVbkPXsj23', 'aNJkSEhjtt', 'iOcjHrm9R8xWXHVrkP', 'fuhlW7qAUmE8DYZHrv', 'Tvbkk4Xbfl', 'tDjkGf3dpI' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, RI5CbnHZJMOX38NIWe.cs |
High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'Jja8bB6lEU', 'NpG8WY4SLZ', 'i5g8z9xtJM', 'llbGpIplh1', 's9gGkAL39b', 'zgOG8XliWj', 'gRYGG5q8Fv', 'OWoDag98XMVVT6ETqbp' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, TVYCZS8CsAAf6xRfPr.cs |
High entropy of concatenated method names: 'abTMGse3k', 'FfQD8fGjE', 'ocWX9F3Qj', 'o7EEysSd2', 'I7yu3gEtP', 'Ye1BG8lwQ', 'I34Ti0u4RcG9Qa7hdb', 'c0F1wry08HThRQ3JtF', 'woQY4oQUq', 'YwOoaVpYZ' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, mT0lgMk0UGmjhglQpy2.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'oNRRJJjkvv', 'CjuRoHlLyi', 'lHLR5jNOxN', 'aT3RRnSxHv', 'e7xRdkc7fx', 'xhKRsaPn3I', 'gVNR2Pxsy6' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, KXppZwBPgJ7E76VbXs.cs |
High entropy of concatenated method names: 'cuulhrjjTF', 'A6alEaKRRv', 'XDDHgVl8Pd', 'PkjHFw6B1X', 'nSdHcJfTXo', 'OoJHL1JuHO', 'SeDHvKtLK0', 'fapHx59X52', 'r99HTYZJSi', 'fJcHCe16Rq' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, nlmoTBWi5RrBNjduPP.cs |
High entropy of concatenated method names: 'v3UoH7e74r', 'r5ColW5onc', 'QEcotKLZDq', 'E6noIJVudW', 'cjyoJEWJf6', 'yCWoKUh9fA', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, T5CUBJkkW6oTYTPm6hD.cs |
High entropy of concatenated method names: 'utQoWGyfoQ', 'EBXozPAXTS', 'vCk5pjR2wW', 'qsf5ktLSs9', 'f2k58Y4chO', 'HvI5G57mZ0', 'I9X50wT2Z7', 'rjT53EdlhF', 'OjE5yVTrP7', 'YmP5q5xPxi' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, qDbtOObWgkLUDUcOmK.cs |
High entropy of concatenated method names: 'cunJ6k4HuC', 'RtjJUh4WPV', 'OldJgCnBv1', 'F1YJFAfh04', 'ArwJcubO61', 'ye1JLGOyeY', 's69JvqD3yP', 'OstJxSfJAf', 'L6VJTTx7vZ', 'FJMJC6wGqb' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, Tgldtnuspxe3w9nTJA.cs |
High entropy of concatenated method names: 'M9wHDRHrdU', 'lPpHXPKqoQ', 'VDPHZGtRXK', 'Xb6HuwNOpL', 'kuGHPAmcBH', 'vpIHSc0G6B', 'p4sHVwZLO6', 'rxtHY6Tmrv', 'CbBHJaf2CW', 'KHRHo7QA90' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, pa30ECvIFvyAltBGSh.cs |
High entropy of concatenated method names: 'tBDIyO21fN', 'iE8IHYIm0a', 'hw3ItxSF45', 'B1rtWHGog3', 'KIItzWhFfb', 'j2sIpCAW4U', 'HVsIkyN3DW', 'UqbI80l6MO', 'FU1IGsgEUS', 'IO9I0U0D91' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, to6tbw1Sv4LCFDGbFJ.cs |
High entropy of concatenated method names: 'KJZ7ZJJeLY', 'l8D7u7wv5m', 'TuI76cIJeD', 'y317UNlsQn', 'LNU7FTlA4i', 'x187ceYm7b', 'del7v1ZEX9', 'pyn7xTJ7u1', 'r0k7CLxjj7', 'OUQ7ja5j8L' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, neicNOfGWVJmDBuMMa.cs |
High entropy of concatenated method names: 'DikVmP2p2L', 'PeIVW2r6qk', 'JYYYpHBxAr', 'qKmYkZRh9D', 'MY3VjXuh8G', 'R89VNoYK3i', 'eXtV1fpGv4', 'KrpV4JsD35', 'lHKVA3upPb', 'AJxViniaRr' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, Rc2muXTKqVZvJsmYO7.cs |
High entropy of concatenated method names: 'cfIIeo0CNR', 'JmhIOHRY7q', 'eh0IMm9UBh', 'nDkIDJR07p', 'qoxIhLi5oB', 'i2oIXM3EfE', 'XQHIEVrjOW', 'ySLIZSAb7Y', 'QxjIu9oM3E', 'lEvIB0OCXs' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, TLjf954KTOhdvwbmoK.cs |
High entropy of concatenated method names: 'TN6PCUfeNQ', 'UIjPNB2QMf', 'IubP4pjyUb', 'xFBPADHqnK', 'twkPUQLnkX', 'wQVPgP0Iet', 'Hr2PFDLgXT', 'yQ6PcVARZE', 'TLRPLLHUji', 'hMMPvfiAEj' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, demNsXKQQ5dOWKyKaT.cs |
High entropy of concatenated method names: 'K0EG3hIdYk', 'nZqGy7xs3s', 'lyyGqyJu0d', 'zCcGHbB18s', 'mOMGlFWd1D', 'c7aGtdJoPg', 'hE8GIADHYc', 'jIHGKFEn6e', 'aUsGnvT6Y0', 'oWxGQvwnQy' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, O23pNJ6EhjttsNQhGK.cs |
High entropy of concatenated method names: 'VqYt3uxTLn', 'FRQtqg3KDy', 'H6rtl4LRLm', 'GRgtIocc4x', 'eXYtKXqBnb', 'LjtlwUL1qE', 'vA7lf8XP7U', 'AN8l9viaIk', 'Ee9lmjH2qK', 'vXMlb9qiZb' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, d5oNk0qNHVBJ02cV5H.cs |
High entropy of concatenated method names: 'Dispose', 'dKNkbKj2BC', 'N6F8U9nZPW', 'xt8nNCcuZx', 'WaPkWj1CsY', 'lAGkzIRUAJ', 'ProcessDialogKey', 'duV8pDbtOO', 'Ygk8kLUDUc', 'ymK887lmoT' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, GnKswFzT5fBSNjTCYX.cs |
High entropy of concatenated method names: 'guZoXFdbJD', 'zaGoZj1VEJ', 'TkxouXkZK9', 'UqKo660TxR', 'dj6oUNCV5S', 'lUdoFCiJwd', 'aEUockj3NL', 'BbSo2DlJTs', 'jjuoeHRPNO', 'JHFoOqssRx' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, anJOVC9Gs0KNKj2BCm.cs |
High entropy of concatenated method names: 'nLBJPSNxIK', 'MX0JV8rTGU', 'zXgJJSJDia', 'hZdJ5VUsh9', 'cQnJdRxPDQ', 'AaZJ2akfLy', 'Dispose', 'qpOYy6aJAf', 'CPxYqCafiQ', 'C9lYHy4aBY' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, iZq82EZ6VPakI888Ti.cs |
High entropy of concatenated method names: 'ETaq4qXUTJ', 'XKJqAsVrDR', 'T8CqiVQ8GZ', 'WFkqr0rMWw', 'kdyqwQf4v5', 'i8tqfUDUg5', 'rgWq93sdG4', 'N7MqmNm0Gq', 'itEqbXKUMv', 'FIWqW9FIZ6' |
Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, QjRGfp0mhEGSXg3p4e.cs |
High entropy of concatenated method names: 'GmtkIZq82E', 'GVPkKakI88', 'lspkQxe3w9', 'lTJkaALXpp', 'GVbkPXsj23', 'aNJkSEhjtt', 'iOcjHrm9R8xWXHVrkP', 'fuhlW7qAUmE8DYZHrv', 'Tvbkk4Xbfl', 'tDjkGf3dpI' |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Users\user\Desktop\9dOKGgFNL2.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\DUBAI-MEDIUM.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\DUBAI-LIGHT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\DUBAI-BOLD.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Users\user\Desktop\9dOKGgFNL2.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\9dOKGgFNL2.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll VolumeInformation |
Jump to behavior |