Click to jump to signature section
Source: Ref_31020563.exe | Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Source: global traffic | HTTP traffic detected: GET /AQBP HTTP/1.1Host: oshi.atConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /AQBP HTTP/1.1Host: oshi.at |
Source: global traffic | HTTP traffic detected: GET /AQBP HTTP/1.1Host: oshi.atConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /AQBP HTTP/1.1Host: oshi.at |
Source: global traffic | HTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Tue, 10 Dec 2024 15:24:29 GMTContent-Type: text/html;charset=UTF-8Content-Length: 1849Connection: close |
Source: Ref_31020563.exe | String found in binary or memory: http://cert.ssl.com/SSL.com-timeStamping-I-RSA-R1.cer0Q |
Source: Ref_31020563.exe | String found in binary or memory: http://cert.ssl.com/SSLcom-SubCA-EV-CodeSigning-RSA-4096-R3.cer0 |
Source: Ref_31020563.exe | String found in binary or memory: http://crls.ssl.com/SSL.com-timeStamping-I-RSA-R1.crl0 |
Source: Ref_31020563.exe | String found in binary or memory: http://crls.ssl.com/SSLcom-RootCA-EV-RSA-4096-R2.crl0 |
Source: Ref_31020563.exe | String found in binary or memory: http://crls.ssl.com/SSLcom-SubCA-EV-CodeSigning-RSA-4096-R3.crl0 |
Source: Ref_31020563.exe | String found in binary or memory: http://crls.ssl.com/ssl.com-rsa-RootCA.crl0 |
Source: Ref_31020563.exe | String found in binary or memory: http://ocsps.ssl.com0 |
Source: Ref_31020563.exe | String found in binary or memory: http://ocsps.ssl.com0? |
Source: Ref_31020563.exe | String found in binary or memory: http://ocsps.ssl.com0_ |
Source: Ref_31020563.exe, 00000000.00000002.2920438184.00000000030EB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://oshi.at |
Source: Ref_31020563.exe, 00000000.00000002.2920438184.00000000030EB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://oshi.atd |
Source: Ref_31020563.exe, 00000000.00000002.2920438184.00000000030DA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: Ref_31020563.exe | String found in binary or memory: http://www.ssl.com/repository/SSLcom-RootCA-EV-RSA-4096-R2.crt0 |
Source: Ref_31020563.exe | String found in binary or memory: http://www.ssl.com/repository/SSLcomRootCertificationAuthorityRSA.crt0 |
Source: Ref_31020563.exe, 00000000.00000002.2920438184.0000000003107000.00000004.00000800.00020000.00000000.sdmp, Ref_31020563.exe, 00000000.00000002.2920438184.000000000310B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/somenonymous/OshiUpload |
Source: Ref_31020563.exe, 00000000.00000002.2920438184.000000000310B000.00000004.00000800.00020000.00000000.sdmp, Ref_31020563.exe, 00000000.00000002.2920438184.00000000030DA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://oshi.at |
Source: Ref_31020563.exe, 00000000.00000002.2920438184.0000000003071000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://oshi.at/AQBP |
Source: Ref_31020563.exe | String found in binary or memory: https://oshi.at/AQBPKPAMhkUWREVZAdqU4bM.xStpkLwqD15MRB9YwOo |
Source: Ref_31020563.exe, 00000000.00000002.2920438184.000000000310B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://oshi.at/AQBPd |
Source: Ref_31020563.exe, 00000000.00000002.2920438184.0000000003071000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://oshi.at/AQBPtocq |
Source: Ref_31020563.exe | String found in binary or memory: https://www.ssl.com/repository0 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49740 |
Source: unknown | Network traffic detected: HTTP traffic on port 49814 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49740 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49814 |
Source: Ref_31020563.exe, 00000000.00000002.2919593971.000000000123E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameclr.dllT vs Ref_31020563.exe |
Source: Ref_31020563.exe, 00000000.00000000.1673474006.0000000000CDB000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameRef#.exe8 vs Ref_31020563.exe |
Source: Ref_31020563.exe | Binary or memory string: OriginalFilenameRef#.exe8 vs Ref_31020563.exe |
Source: classification engine | Classification label: mal56.winEXE@1/0@1/1 |
Source: Ref_31020563.exe | Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: Ref_31020563.exe | Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Memory allocated: 1410000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Memory allocated: 3070000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Memory allocated: 5070000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 599766 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 599656 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 599547 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 599435 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 599328 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 599219 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 599094 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598984 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598875 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598766 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598656 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598547 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598437 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598328 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598219 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598094 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597984 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597875 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597765 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597656 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597547 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597437 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597327 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597215 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597109 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597000 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 596891 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 596766 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 596641 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 596531 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 596422 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 596305 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 596203 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 596094 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595984 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595875 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595766 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595641 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595516 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595406 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595295 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595187 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595078 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 594968 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 594859 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 594750 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 594640 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 594531 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep count: 35 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -32281802128991695s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -599875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8036 | Thread sleep count: 8512 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8036 | Thread sleep count: 1340 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -599766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -599656s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -599547s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -599435s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -599328s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -599219s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -599094s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -598984s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -598875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -598766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -598656s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -598547s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -598437s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -598328s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -598219s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -598094s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -597984s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -597875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -597765s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -597656s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -597547s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -597437s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -597327s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -597215s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -597109s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -597000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -596891s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -596766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -596641s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -596531s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -596422s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -596305s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -596203s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -596094s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -595984s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -595875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -595766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -595641s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -595516s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -595406s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -595295s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -595187s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -595078s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -594968s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -594859s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -594750s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -594640s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe TID: 8032 | Thread sleep time: -594531s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 599766 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 599656 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 599547 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 599435 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 599328 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 599219 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 599094 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598984 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598875 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598766 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598656 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598547 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598437 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598328 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598219 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 598094 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597984 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597875 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597765 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597656 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597547 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597437 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597327 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597215 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597109 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 597000 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 596891 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 596766 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 596641 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 596531 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 596422 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 596305 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 596203 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 596094 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595984 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595875 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595766 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595641 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595516 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595406 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595295 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595187 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 595078 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 594968 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 594859 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 594750 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 594640 | Jump to behavior |
Source: C:\Users\user\Desktop\Ref_31020563.exe | Thread delayed: delay time: 594531 | Jump to behavior |
Source: Ref_31020563.exe, 00000000.00000002.2919593971.00000000012AD000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll' |