Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FEC087 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,FindNextFileA, | 0_2_00FEC087 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FF61AE wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,StrCmpCA,wsprintfA,wsprintfA,PathMatchSpecA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, | 0_2_00FF61AE |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FEBA79 FindFirstFileA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, | 0_2_00FEBA79 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FF5CE8 GetProcessHeap,HeapAlloc,wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,lstrcatA,lstrcatA,lstrlenA,lstrlenA, | 0_2_00FF5CE8 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FE9DAF FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,StrCmpCA,StrCmpCA,StrCmpCA,_memset,lstrcatA,lstrcatA,lstrcatA,_memset,lstrcatA,lstrcatA,lstrcatA,StrCmpCA,CopyFileA,StrCmpCA,DeleteFileA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, | 0_2_00FE9DAF |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FE1D70 FindFirstFileA,StrCmpCA,StrCmpCA,FindFirstFileA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,CopyFileA,DeleteFileA,FindNextFileA,FindClose, | 0_2_00FE1D70 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FECEEB wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,lstrlenA,DeleteFileA,CopyFileA,FindNextFileA,FindClose, | 0_2_00FECEEB |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FF4EA5 wsprintfA,FindFirstFileA,_memset,_memset,StrCmpCA,StrCmpCA,wsprintfA,StrCmpCA,wsprintfA,wsprintfA,_memset,lstrcatA,strtok_s,strtok_s,_memset,lstrcatA,strtok_s,PathMatchSpecA,DeleteFileA,CopyFileA,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,DeleteFileA,strtok_s,strtok_s,FindNextFileA,FindClose, | 0_2_00FF4EA5 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FF561A wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,FindNextFileA,FindClose, | 0_2_00FF561A |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FED77A FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, | 0_2_00FED77A |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FEB719 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,FindNextFileA,FindClose, | 0_2_00FEB719 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_6CD6717D FindFirstFileExW, | 0_2_6CD6717D |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://127.0.0.1:27060 |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: http://store.steampowered.com/account/cookiepreferences/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: http://store.steampowered.com/privacy_agreement/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: http://store.steampowered.com/subscriber_agreement/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: http://www.valvesoftware.com/legal.htm |
Source: njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://api.steampowered.com/ |
Source: 76561199794498376[1].htm.0.dr | String found in binary or memory: https://avatars.cloudflare.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://broadcast.st.dl.eccdnx.com |
Source: njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://cdn.cloudflare.steamstatic.com/steamcommunity/public/assets/ |
Source: njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://checkout.steampowered.com/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp | String found in binary or memory: https://community.cloudflare.steamstat |
Source: njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://community.cloudflare.steamstatic.com/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/css/applications/community/main.css?v=LjouqOsWbS |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/css/globalv2.css?v=i_iuPUaT8LXN&l=english&am |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/css/promo/summer2017/stickers.css?v=INiZALwvDIbb |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/css/skin_1/header.css?v=EZbG2DEumYDH&l=engli |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/css/skin_1/modalContent.css?v=WXAusLHclDIt&l |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/css/skin_1/profilev2.css?v=l1VAyDrxeeyo&l=en |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/images/skin_1/arrowDn9x5.gif |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1 |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/javascript/applications/community/libraries~b28b |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/javascript/applications/community/main.js?v=Cx79 |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/javascript/applications/community/manifest.js?v= |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/javascript/global.js?v=3W_ge11SZngF&l=englis |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=gQHVlrK4-jX-&a |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/javascript/modalContent.js?v=XfYrwi9zUC4b&l= |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/javascript/modalv2.js?v=zBXEuexVQ0FZ&l=engli |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/javascript/profile.js?v=47omfdMZRDiz&l=engli |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/javascript/promo/stickers.js?v=iGFW_JMULCcZ& |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/javascript/prototype-1.7.js?v=npJElBnrEO6W&l |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/javascript/reportedcontent.js |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/javascript/reportedcontent.js?v=-lZqrarogJr8& |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=pbdAKOcD |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/javascript/webui/clientcom.js?v=ImL_uti9QFBw& |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/shared/css/buttons.css?v=G3UTKgHH4xLD&l=engl |
Source: 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/shared/css/motiva_sans.css?v=nc69vwog8R9p&l= |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/shared/css/shared_global.css?v=bpFp7zU77IKn& |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/shared/css/shared_responsive.css?v=n4_f9JKDa7wP& |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016 |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/shared/images/responsive/header_logo.png |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.p |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/shared/javascript/auth_refresh.js?v=w6QbwI-5-j2S |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/shared/javascript/shared_global.js?v=0y-Qdz9keFm |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/shared/javascript/toolti |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://community.cloudflare.steamstatic.com/public/shared/javascript/tooltip.js?v=QYkT4eS5mbTN& |
Source: njrtdhadawt.exe, chrome.dll.0.dr | String found in binary or memory: https://docs.rs/getrandom#nodejs-es-module-support |
Source: njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://help.steampowered.com/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://help.steampowered.com/en/ |
Source: njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.steampowered.com/ |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lv.queniujq.cn |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://medal.tv |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://player.vimeo.com |
Source: njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://recaptcha.net |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://recaptcha.net/recaptcha/; |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://s.ytimg.com; |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://sketchfab.com |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steam.tv/ |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steambroadcast-test.akamaized.net |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steambroadcast.akamaized.net |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steambroadcastchat.akamaized.net |
Source: 76561199794498376[1].htm.0.dr | String found in binary or memory: https://steamcommunity.com/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://steamcommunity.com/?subsection=broadcasts |
Source: njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steamcommunity.com/Y |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://steamcommunity.com/discussions/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org |
Source: njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steamcommunity.com/linkfilter/?u=http%d- |
Source: 76561199794498376[1].htm.0.dr | String found in binary or memory: https://steamcommunity.com/login/home/?goto=profiles%2F76561199794498376 |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://steamcommunity.com/market/ |
Source: njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://steamcommunity.com/my/wishlist/ |
Source: njrtdhadawt.exe | String found in binary or memory: https://steamcommunity.com/profiles/76561199794498376 |
Source: njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://steamcommunity.com/profiles/76561199794498376) |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://steamcommunity.com/profiles/76561199794498376/badges |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://steamcommunity.com/profiles/76561199794498376/inventory/ |
Source: njrtdhadawt.exe | String found in binary or memory: https://steamcommunity.com/profiles/76561199794498376idr7ffMozilla/5.0 |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://steamcommunity.com/workshop/ |
Source: 76561199794498376[1].htm.0.dr | String found in binary or memory: https://store.steampowered.com/ |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://store.steampowered.com/; |
Source: 76561199794498376[1].htm.0.dr | String found in binary or memory: https://store.steampowered.com/about/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://store.steampowered.com/explore/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://store.steampowered.com/legal/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://store.steampowered.com/mobile |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://store.steampowered.com/news/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://store.steampowered.com/points/shop/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://store.steampowered.com/privacy_agreement/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://store.steampowered.com/stats/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://store.steampowered.com/steam_refunds/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000003.1539350071.0000000003A07000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://store.steampowered.com/subscriber_agreement/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp | String found in binary or memory: https://t.me/a |
Source: njrtdhadawt.exe | String found in binary or memory: https://t.me/asg7rd |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://t.me/asg7rdU_ |
Source: njrtdhadawt.exe | String found in binary or memory: https://t.me/asg7rdidr7ffsqlo.dllMozilla/5.0 |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://t.me/nj |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://t.me/zj |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://telegram.org/img/t_logo_2x.png |
Source: njrtdhadawt.exe, 00000000.00000003.1510994054.00000000039DB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://web.telegram.org |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com |
Source: njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/recaptcha/ |
Source: njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.gstatic.cn/recaptcha/ |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.gstatic.com/recaptcha/ |
Source: njrtdhadawt.exe, 00000000.00000002.1550787502.00000000010EC000.00000004.00000001.01000000.00000003.sdmp, njrtdhadawt.exe, 00000000.00000002.1551342830.00000000039B3000.00000004.00000020.00020000.00000000.sdmp, 76561199794498376[1].htm.0.dr | String found in binary or memory: https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.youtube.com |
Source: njrtdhadawt.exe, 00000000.00000002.1551342830.0000000003998000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, njrtdhadawt.exe, 00000000.00000003.1539387427.00000000039C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.youtube.com/ |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: windows.fileexplorer.common.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FEC087 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,FindNextFileA, | 0_2_00FEC087 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FF61AE wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,StrCmpCA,wsprintfA,wsprintfA,PathMatchSpecA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, | 0_2_00FF61AE |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FEBA79 FindFirstFileA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, | 0_2_00FEBA79 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FF5CE8 GetProcessHeap,HeapAlloc,wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,lstrcatA,lstrcatA,lstrlenA,lstrlenA, | 0_2_00FF5CE8 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FE9DAF FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,StrCmpCA,StrCmpCA,StrCmpCA,_memset,lstrcatA,lstrcatA,lstrcatA,_memset,lstrcatA,lstrcatA,lstrcatA,StrCmpCA,CopyFileA,StrCmpCA,DeleteFileA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, | 0_2_00FE9DAF |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FE1D70 FindFirstFileA,StrCmpCA,StrCmpCA,FindFirstFileA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,CopyFileA,DeleteFileA,FindNextFileA,FindClose, | 0_2_00FE1D70 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FECEEB wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,lstrlenA,DeleteFileA,CopyFileA,FindNextFileA,FindClose, | 0_2_00FECEEB |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FF4EA5 wsprintfA,FindFirstFileA,_memset,_memset,StrCmpCA,StrCmpCA,wsprintfA,StrCmpCA,wsprintfA,wsprintfA,_memset,lstrcatA,strtok_s,strtok_s,_memset,lstrcatA,strtok_s,PathMatchSpecA,DeleteFileA,CopyFileA,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,DeleteFileA,strtok_s,strtok_s,FindNextFileA,FindClose, | 0_2_00FF4EA5 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FF561A wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,FindNextFileA,FindClose, | 0_2_00FF561A |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FED77A FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, | 0_2_00FED77A |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_00FEB719 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,FindNextFileA,FindClose, | 0_2_00FEB719 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: 0_2_6CD6717D FindFirstFileExW, | 0_2_6CD6717D |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: GetKeyboardLayoutList,LocalAlloc,GetKeyboardLayoutList,GetLocaleInfoA,LocalFree, | 0_2_00FF0FFE |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: GetLocaleInfoA, | 0_2_0100E144 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,InterlockedDecrement,InterlockedDecrement,_free,_free, | 0_2_0100980E |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: GetLocaleInfoA,_LocaleUpdate::_LocaleUpdate,___ascii_strnicmp,__tolower_l,__tolower_l, | 0_2_0100E00F |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat, | 0_2_01007016 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA, | 0_2_0100B020 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo, | 0_2_01008864 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: _strlen,_GetPrimaryLen,EnumSystemLocalesA, | 0_2_0100B087 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: __getptd,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoA,strcpy_s,__invoke_watson,GetLocaleInfoA,GetLocaleInfoA,__itow_s, | 0_2_0100B0C3 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, | 0_2_0100AB6C |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: GetLocaleInfoW,_GetPrimaryLen,_strlen, | 0_2_0100AD08 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,_strlen,GetLocaleInfoA,_strlen,_TestDefaultLanguage, | 0_2_0100AD63 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtGetStringTypeA,___crtLCMapStringA,___crtLCMapStringA,_memmove,_memmove,_memmove,InterlockedDecrement,_free,_free,_free,_free,_free,_free,_free,_free,_free,InterlockedDecrement, | 0_2_0100A5E0 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: __getptd,_LcidFromHexString,GetLocaleInfoA, | 0_2_0100AC61 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,InterlockedDecrement,InterlockedDecrement,InterlockedDecrement,_free,_free, | 0_2_010094F0 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage, | 0_2_0100AF34 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,malloc,GetLocaleInfoW,WideCharToMultiByte,__freea, | 0_2_01006F3C |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: EnumSystemLocalesA, | 0_2_0100AFF6 |
Source: C:\Users\user\Desktop\njrtdhadawt.exe | Code function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__invoke_watson,GetLocaleInfoW,GetLocaleInfoW,__calloc_crt,GetLocaleInfoW,_free,GetLocaleInfoW, | 0_2_01004E83 |