Source: | Binary string: System.Windows.Forms.pdbL source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Xml.ni.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.ni.pdbRSDS source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Windows.Forms.ni.pdb source: T05Dk6G8fg.exe, 00000001.00000002.43990776194.00000000715AE000.00000020.00000001.01000000.00000008.sdmp, WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Core.pdb\ source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Drawing.ni.pdb source: T05Dk6G8fg.exe, 00000001.00000002.44003035098.000000007178B000.00000020.00000001.01000000.00000007.sdmp, WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Net.Http.pdbi source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Configuration.ni.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Net.Http.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Security.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.IO.Compression.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Configuration.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Drawing.ni.pdbRSDS source: T05Dk6G8fg.exe, 00000001.00000002.44003035098.000000007178B000.00000020.00000001.01000000.00000007.sdmp, WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Xml.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Xml.ni.pdbRSDS# source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Core.ni.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.pdbTL source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Windows.Forms.ni.pdbRSDSX source: T05Dk6G8fg.exe, 00000001.00000002.43990776194.00000000715AE000.00000020.00000001.01000000.00000008.sdmp, WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Windows.Forms.pdb source: T05Dk6G8fg.exe, 00000001.00000002.43990776194.00000000715AE000.00000020.00000001.01000000.00000008.sdmp, WERF69D.tmp.dmp.19.dr |
Source: | Binary string: mscorlib.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: mscorlib.ni.pdbRSDSrMV9 source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Net.Http.ni.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Drawing.pdb source: T05Dk6G8fg.exe, 00000001.00000002.44003035098.000000007178B000.00000020.00000001.01000000.00000007.sdmp, WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Management.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: mscorlib.ni.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Management.ni.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Core.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Configuration.pdbH source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Configuration.ni.pdbRSDScUN source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Net.Http.ni.pdbRSDS source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Management.ni.pdbRSDS6 source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.ni.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Core.ni.pdbRSDS source: WERF69D.tmp.dmp.19.dr |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: T05Dk6G8fg.exe, 00000001.00000002.43974342595.0000000002FD4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://89.23.100.233:1488 |
Source: T05Dk6G8fg.exe, 00000001.00000002.43974342595.0000000002FD4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://89.23.100.233:1488/uploadt |
Source: T05Dk6G8fg.exe, 00000001.00000002.43990776194.0000000070E90000.00000020.00000001.01000000.00000008.sdmp | String found in binary or memory: http://beta.visualstudio.net/net/sdk/feedback.asp |
Source: T05Dk6G8fg.exe, 00000001.00000002.43974342595.0000000002F27000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://icanhazip.com |
Source: T05Dk6G8fg.exe, 00000001.00000002.43974342595.0000000002F27000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://icanhazip.com/ |
Source: T05Dk6G8fg.exe, 00000001.00000002.43974342595.0000000002F27000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: tmpD36E.tmp.dat.1.dr | String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: tmpD36E.tmp.dat.1.dr | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: tmpD36E.tmp.dat.1.dr | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: T05Dk6G8fg.exe, 00000001.00000002.43986346912.00000000076ED000.00000004.00000020.00020000.00000000.sdmp, T05Dk6G8fg.exe, 00000001.00000002.43978325790.0000000003F69000.00000004.00000800.00020000.00000000.sdmp, T05Dk6G8fg.exe, 00000001.00000002.43978325790.0000000004006000.00000004.00000800.00020000.00000000.sdmp, T05Dk6G8fg.exe, 00000001.00000002.43978325790.0000000003F89000.00000004.00000800.00020000.00000000.sdmp, tmpD370.tmp.dat.1.dr, tmpD36D.tmp.dat.1.dr, tmpD36E.tmp.dat.1.dr | String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: tmpD36E.tmp.dat.1.dr | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: tmpD36E.tmp.dat.1.dr | String found in binary or memory: https://gemini.google.com/app?q= |
Source: T05Dk6G8fg.exe, 00000001.00000002.43986346912.00000000076ED000.00000004.00000020.00020000.00000000.sdmp, T05Dk6G8fg.exe, 00000001.00000002.43978325790.0000000003F69000.00000004.00000800.00020000.00000000.sdmp, T05Dk6G8fg.exe, 00000001.00000002.43978325790.0000000004006000.00000004.00000800.00020000.00000000.sdmp, T05Dk6G8fg.exe, 00000001.00000002.43978325790.0000000003F89000.00000004.00000800.00020000.00000000.sdmp, tmpD370.tmp.dat.1.dr, tmpD36D.tmp.dat.1.dr, tmpD36E.tmp.dat.1.dr | String found in binary or memory: https://uk.search.yahoo.com/favicon.icohttps://uk.search.yahoo.com/search |
Source: T05Dk6G8fg.exe, 00000001.00000002.43986346912.00000000076ED000.00000004.00000020.00020000.00000000.sdmp, T05Dk6G8fg.exe, 00000001.00000002.43978325790.0000000003F69000.00000004.00000800.00020000.00000000.sdmp, T05Dk6G8fg.exe, 00000001.00000002.43978325790.0000000004006000.00000004.00000800.00020000.00000000.sdmp, T05Dk6G8fg.exe, 00000001.00000002.43978325790.0000000003F89000.00000004.00000800.00020000.00000000.sdmp, tmpD370.tmp.dat.1.dr, tmpD36D.tmp.dat.1.dr, tmpD36E.tmp.dat.1.dr | String found in binary or memory: https://uk.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: T05Dk6G8fg.exe, 00000001.00000002.43986346912.00000000076ED000.00000004.00000020.00020000.00000000.sdmp, T05Dk6G8fg.exe, 00000001.00000002.43978325790.0000000003F69000.00000004.00000800.00020000.00000000.sdmp, T05Dk6G8fg.exe, 00000001.00000002.43978325790.0000000004006000.00000004.00000800.00020000.00000000.sdmp, T05Dk6G8fg.exe, 00000001.00000002.43978325790.0000000003F89000.00000004.00000800.00020000.00000000.sdmp, tmpD370.tmp.dat.1.dr, tmpD36D.tmp.dat.1.dr, tmpD36E.tmp.dat.1.dr | String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: T05Dk6G8fg.exe, 00000001.00000002.43974342595.0000000002FD4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com |
Source: tmpD36E.tmp.dat.1.dr | String found in binary or memory: https://www.google.com/favicon.ico |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB4AA0 NtOpenFile, | 1_2_02EB4AA0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB4B78 NtCreateSection, | 1_2_02EB4B78 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB41C8 NtClose, | 1_2_02EB41C8 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB4ED8 NtDeviceIoControlFile, | 1_2_02EB4ED8 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB4680 NtProtectVirtualMemory, | 1_2_02EB4680 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB4E10 NtQueryVolumeInformationFile, | 1_2_02EB4E10 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB4758 NtAllocateVirtualMemory, | 1_2_02EB4758 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB4D20 NtMapViewOfSection, | 1_2_02EB4D20 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB4A98 NtOpenFile, | 1_2_02EB4A98 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB4B70 NtCreateSection, | 1_2_02EB4B70 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB41C1 NtClose, | 1_2_02EB41C1 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB4ED1 NtDeviceIoControlFile, | 1_2_02EB4ED1 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB4678 NtProtectVirtualMemory, | 1_2_02EB4678 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB4E08 NtQueryVolumeInformationFile, | 1_2_02EB4E08 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB4751 NtAllocateVirtualMemory, | 1_2_02EB4751 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB4D18 NtMapViewOfSection, | 1_2_02EB4D18 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_0152A150 | 1_2_0152A150 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_0152D970 | 1_2_0152D970 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_01529848 | 1_2_01529848 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_01521098 | 1_2_01521098 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_0152C098 | 1_2_0152C098 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_01528BA8 | 1_2_01528BA8 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_01528C98 | 1_2_01528C98 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_0152BE98 | 1_2_0152BE98 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_01529846 | 1_2_01529846 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_0152A000 | 1_2_0152A000 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_01521096 | 1_2_01521096 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_01528B50 | 1_2_01528B50 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_0152BB29 | 1_2_0152BB29 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_01528B98 | 1_2_01528B98 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_01529D7A | 1_2_01529D7A |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_01529D99 | 1_2_01529D99 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_01529D9E | 1_2_01529D9E |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_01529DA0 | 1_2_01529DA0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_01520B70 | 1_2_01520B70 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_015294D8 | 1_2_015294D8 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_015294C7 | 1_2_015294C7 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_01528C88 | 1_2_01528C88 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_01529FF0 | 1_2_01529FF0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_0152BE89 | 1_2_0152BE89 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB3AE0 | 1_2_02EB3AE0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB6380 | 1_2_02EB6380 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB8B58 | 1_2_02EB8B58 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB39A0 | 1_2_02EB39A0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB0ED0 | 1_2_02EB0ED0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB3698 | 1_2_02EB3698 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EBD750 | 1_2_02EBD750 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EBDF00 | 1_2_02EBDF00 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB24C0 | 1_2_02EB24C0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EBCD20 | 1_2_02EBCD20 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB7240 | 1_2_02EB7240 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EBDF00 | 1_2_02EBDF00 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB1360 | 1_2_02EB1360 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB20C0 | 1_2_02EB20C0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB3970 | 1_2_02EB3970 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB8120 | 1_2_02EB8120 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB8111 | 1_2_02EB8111 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB0EC1 | 1_2_02EB0EC1 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EB4FB0 | 1_2_02EB4FB0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EBCC88 | 1_2_02EBCC88 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_02EBCD10 | 1_2_02EBCD10 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CDE6C8 | 1_2_06CDE6C8 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CD9658 | 1_2_06CD9658 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CD47C8 | 1_2_06CD47C8 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CD2F8A | 1_2_06CD2F8A |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CDDCF0 | 1_2_06CDDCF0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CD54BA | 1_2_06CD54BA |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CDEC70 | 1_2_06CDEC70 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CD2540 | 1_2_06CD2540 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CD9AC0 | 1_2_06CD9AC0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CD3B98 | 1_2_06CD3B98 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CDCB27 | 1_2_06CDCB27 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CDC8E0 | 1_2_06CDC8E0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CD60A0 | 1_2_06CD60A0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CD0040 | 1_2_06CD0040 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CDE685 | 1_2_06CDE685 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CDD7C5 | 1_2_06CDD7C5 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CDD790 | 1_2_06CDD790 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CD0CE3 | 1_2_06CD0CE3 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CD95D8 | 1_2_06CD95D8 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CD2532 | 1_2_06CD2532 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CDE2ED | 1_2_06CDE2ED |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CDE3CF | 1_2_06CDE3CF |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CDA39A | 1_2_06CDA39A |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CDE3AF | 1_2_06CDE3AF |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CD43B0 | 1_2_06CD43B0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CD0B77 | 1_2_06CD0B77 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CDC8D1 | 1_2_06CDC8D1 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CD3828 | 1_2_06CD3828 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_06CD5170 | 1_2_06CD5170 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08182818 | 1_2_08182818 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08185C00 | 1_2_08185C00 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08186E00 | 1_2_08186E00 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08187E38 | 1_2_08187E38 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08180040 | 1_2_08180040 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08186079 | 1_2_08186079 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_0818DA65 | 1_2_0818DA65 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08186680 | 1_2_08186680 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_081870F8 | 1_2_081870F8 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_0818C6E8 | 1_2_0818C6E8 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08185F0A | 1_2_08185F0A |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08189128 | 1_2_08189128 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08184970 | 1_2_08184970 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08185D75 | 1_2_08185D75 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_081863D0 | 1_2_081863D0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_081899D3 | 1_2_081899D3 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08185613 | 1_2_08185613 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08184E35 | 1_2_08184E35 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08187E27 | 1_2_08187E27 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08189C50 | 1_2_08189C50 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08188AC8 | 1_2_08188AC8 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_0818A0E0 | 1_2_0818A0E0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08188B10 | 1_2_08188B10 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08182170 | 1_2_08182170 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_0818AFB8 | 1_2_0818AFB8 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08181FB0 | 1_2_08181FB0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_081893D7 | 1_2_081893D7 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_081893F0 | 1_2_081893F0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_0818BDE8 | 1_2_0818BDE8 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_081851ED | 1_2_081851ED |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_0819CB0F | 1_2_0819CB0F |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08197238 | 1_2_08197238 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_0819D028 | 1_2_0819D028 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08197C20 | 1_2_08197C20 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08190040 | 1_2_08190040 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08192443 | 1_2_08192443 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_081943D0 | 1_2_081943D0 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08193F4C | 1_2_08193F4C |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08191A90 | 1_2_08191A90 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_081960D8 | 1_2_081960D8 |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Code function: 1_2_08191AF0 | 1_2_08191AF0 |
Source: unknown | Process created: C:\Users\user\Desktop\T05Dk6G8fg.exe "C:\Users\user\Desktop\T05Dk6G8fg.exe" | |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c tasklist | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd" /C chcp 65001 && netsh wlan show profiles | findstr All | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\chcp.com chcp 65001 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\netsh.exe netsh wlan show profiles | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr All | |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C C:\Users\user\AppData\Local\Temp\tmpBA88.tmp.bat & Del C:\Users\user\AppData\Local\Temp\tmpBA88.tmp.bat | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\chcp.com chcp 65001 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\taskkill.exe TaskKill /F /IM 2956 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe Timeout /T 2 /Nobreak | |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 2956 -s 2948 | |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c tasklist | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd" /C chcp 65001 && netsh wlan show profiles | findstr All | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C C:\Users\user\AppData\Local\Temp\tmpBA88.tmp.bat & Del C:\Users\user\AppData\Local\Temp\tmpBA88.tmp.bat | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\chcp.com chcp 65001 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\netsh.exe netsh wlan show profiles | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr All | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\chcp.com chcp 65001 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\taskkill.exe TaskKill /F /IM 2956 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe Timeout /T 2 /Nobreak | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\chcp.com | Section loaded: ulib.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\chcp.com | Section loaded: fsutilext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ifmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mprapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasmontr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mfc42u.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: authfwcfg.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwpolicyiomgr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: firewallapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dhcpcmonitor.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dot3cfg.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dot3api.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: onex.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: eappcfg.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: eappprxy.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwcfg.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: hnetmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netshell.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netsetupapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netiohlp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshhttp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: httpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshipsec.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: activeds.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: polstore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winipsec.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: adsldpc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: adsldpc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshwfp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: p2pnetsh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: p2p.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rpcnsh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: whhelper.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wlancfg.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wlanapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wshelper.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wevtapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: peerdistsh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wcmapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rmclient.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mobilenetworking.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ktmw32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mprmsg.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\findstr.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\chcp.com | Section loaded: ulib.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\chcp.com | Section loaded: fsutilext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: | Binary string: System.Windows.Forms.pdbL source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Xml.ni.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.ni.pdbRSDS source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Windows.Forms.ni.pdb source: T05Dk6G8fg.exe, 00000001.00000002.43990776194.00000000715AE000.00000020.00000001.01000000.00000008.sdmp, WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Core.pdb\ source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Drawing.ni.pdb source: T05Dk6G8fg.exe, 00000001.00000002.44003035098.000000007178B000.00000020.00000001.01000000.00000007.sdmp, WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Net.Http.pdbi source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Configuration.ni.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Net.Http.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Security.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.IO.Compression.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Configuration.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Drawing.ni.pdbRSDS source: T05Dk6G8fg.exe, 00000001.00000002.44003035098.000000007178B000.00000020.00000001.01000000.00000007.sdmp, WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Xml.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Xml.ni.pdbRSDS# source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Core.ni.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.pdbTL source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Windows.Forms.ni.pdbRSDSX source: T05Dk6G8fg.exe, 00000001.00000002.43990776194.00000000715AE000.00000020.00000001.01000000.00000008.sdmp, WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Windows.Forms.pdb source: T05Dk6G8fg.exe, 00000001.00000002.43990776194.00000000715AE000.00000020.00000001.01000000.00000008.sdmp, WERF69D.tmp.dmp.19.dr |
Source: | Binary string: mscorlib.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: mscorlib.ni.pdbRSDSrMV9 source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Net.Http.ni.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Drawing.pdb source: T05Dk6G8fg.exe, 00000001.00000002.44003035098.000000007178B000.00000020.00000001.01000000.00000007.sdmp, WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Management.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: mscorlib.ni.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Management.ni.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Core.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Configuration.pdbH source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Configuration.ni.pdbRSDScUN source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Net.Http.ni.pdbRSDS source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Management.ni.pdbRSDS6 source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.ni.pdb source: WERF69D.tmp.dmp.19.dr |
Source: | Binary string: System.Core.ni.pdbRSDS source: WERF69D.tmp.dmp.19.dr |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\T05Dk6G8fg.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |