Source: PagefileConfig.exe |
String found in binary or memory: http://ocsp.comodoca.com0 |
Source: PagefileConfig.exe |
String found in binary or memory: http://www.autoitscript.com/atools/ |
Source: PagefileConfig.exe, ConDrv.0.dr |
String found in binary or memory: http://www.autoitscript.com/tools |
Source: PagefileConfig.exe |
String found in binary or memory: http://www.autoitscript.com/tools: |
Source: PagefileConfig.exe |
String found in binary or memory: http://www.autoitscript.com/toolsB |
Source: PagefileConfig.exe |
String found in binary or memory: http://www.autoitscript.com/toolsThis |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: 0_2_0079F260 |
0_2_0079F260 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: 0_2_00799362 |
0_2_00799362 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: 0_2_00799736 |
0_2_00799736 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: 0_2_007A27CF |
0_2_007A27CF |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: 0_2_00799B42 |
0_2_00799B42 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: 0_2_00798E8D |
0_2_00798E8D |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: 0_2_00799F62 |
0_2_00799F62 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: String function: 0079FEA0 appears 49 times |
|
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: String function: 0079AF0E appears 37 times |
|
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: String function: 00788591 appears 32 times |
|
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: String function: 0079AEDB appears 182 times |
|
Source: PagefileConfig.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: PagefileConfig.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: PagefileConfig.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: PagefileConfig.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: PagefileConfig.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: 0_2_007A6DF4 LoadLibraryA,GetProcAddress,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer, |
0_2_007A6DF4 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Evasive API call chain: GetModuleFileName,DecisionNodes,Sleep |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Evasive API call chain: GetModuleFileName,DecisionNodes,ExitProcess |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: 0_2_007A6DF4 LoadLibraryA,GetProcAddress,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer, |
0_2_007A6DF4 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: 0_2_007985B2 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
0_2_007985B2 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: 0_2_007A1742 SetUnhandledExceptionFilter, |
0_2_007A1742 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: 0_2_0079DC7A __NMSG_WRITE,_raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_0079DC7A |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: 0_2_00798D15 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
0_2_00798D15 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: 0_2_0078BE8D _abort,__NMSG_WRITE,_raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_0078BE8D |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: GetLocaleInfoA, |
0_2_0079F038 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: GetLocaleInfoA,GetLocaleInfoA,GetACP, |
0_2_007A603D |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA, |
0_2_007A6154 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: __crtGetLocaleInfoA_stat, |
0_2_007A711B |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: GetLocaleInfoA,_LcidFromHexString,_GetPrimaryLen,_strlen, |
0_2_007A61EC |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,_strlen,GetLocaleInfoA,_strlen,_TestDefaultLanguage, |
0_2_007A6260 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo, |
0_2_007A52DF |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,__invoke_watson,___crtGetLocaleInfoW, |
0_2_007A1349 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtGetStringTypeA,___crtLCMapStringA,___crtLCMapStringA,InterlockedDecrement,InterlockedDecrement, |
0_2_0079C3EE |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage, |
0_2_007A6432 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA, |
0_2_007A64F3 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: _strlen,_GetPrimaryLen,EnumSystemLocalesA, |
0_2_007A655A |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: __getptd,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,_ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoA,_strcpy_s,__invoke_watson,GetLocaleInfoA,GetLocaleInfoA,__itoa_s, |
0_2_007A6596 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: __calloc_crt,__malloc_crt,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,InterlockedDecrement,InterlockedDecrement,InterlockedDecrement, |
0_2_007A594D |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: GetLocaleInfoA, |
0_2_007A4AAF |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: __calloc_crt,__malloc_crt,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,InterlockedDecrement,InterlockedDecrement, |
0_2_007A5BA5 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetLastError,GetLocaleInfoW,_malloc,GetLocaleInfoW,WideCharToMultiByte,__freea,GetLocaleInfoA, |
0_2_007A6FDC |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: GetLocaleInfoW, |
0_2_007A6FA8 |
Source: C:\Users\user\Desktop\PagefileConfig.exe |
Code function: GetLocaleInfoA,___ascii_strnicmp,__tolower_l,__tolower_l, |
0_2_007A7F85 |