Source: | Binary string: System.Xml.ni.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: C:\Users\Malware\source\repos\ConsoleApplication2\x64\Release\ConsoleApplication2.pdb source: bPkG0wTVon.exe |
Source: | Binary string: C:\Users\Raifon\source\repos\Arcana\Arcana\bin\Release\Arcana.pdb source: bPkG0wTVon.exe |
Source: | Binary string: System.ni.pdbRSDS source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: \??\C:\Users\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\tdata source: bPkG0wTVon.exe, 00000000.00000002.1506746297.00000000076C9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Windows.Forms.ni.pdb source: bPkG0wTVon.exe, 00000000.00000002.1512294678.0000000070A0B000.00000020.00000001.01000000.00000007.sdmp, WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Management.pdbt source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Drawing.ni.pdb source: bPkG0wTVon.exe, 00000000.00000002.1524377559.0000000070BEB000.00000020.00000001.01000000.00000006.sdmp, WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Configuration.ni.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Net.Http.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Security.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Configuration.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Drawing.ni.pdbRSDS source: bPkG0wTVon.exe, 00000000.00000002.1524377559.0000000070BEB000.00000020.00000001.01000000.00000006.sdmp, WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Xml.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Xml.ni.pdbRSDS# source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Core.ni.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Windows.Forms.pdb source: bPkG0wTVon.exe, 00000000.00000002.1512294678.0000000070A0B000.00000020.00000001.01000000.00000007.sdmp, WERB95F.tmp.dmp.24.dr |
Source: | Binary string: mscorlib.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: \??\C:\Users\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\*ata source: bPkG0wTVon.exe, 00000000.00000002.1506746297.00000000076C9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.ni.pdbRSDSJ< source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Windows.Forms.ni.pdbRSDS source: bPkG0wTVon.exe, 00000000.00000002.1512294678.0000000070A0B000.00000020.00000001.01000000.00000007.sdmp, WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Net.Http.ni.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Management.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Drawing.pdb source: bPkG0wTVon.exe, 00000000.00000002.1524377559.0000000070BEB000.00000020.00000001.01000000.00000006.sdmp, WERB95F.tmp.dmp.24.dr |
Source: | Binary string: mscorlib.ni.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Management.ni.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: Arcana.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Core.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Configuration.pdbH source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: mscorlib.ni.pdbRSDS] source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.pdbp source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: C:\Users\Malware\source\repos\ConsoleApplication2\x64\Release\ConsoleApplication2.pdb" source: bPkG0wTVon.exe |
Source: | Binary string: System.Configuration.ni.pdbRSDScUN source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Net.Http.ni.pdbRSDS source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.ni.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Core.ni.pdbRSDS source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Web.pdb source: WERB95F.tmp.dmp.24.dr |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.23.100.233 |
Source: bPkG0wTVon.exe, 00000000.00000002.1495190259.0000000002A03000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://89.23.100.233:1490 |
Source: bPkG0wTVon.exe, 00000000.00000002.1495190259.0000000002872000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://89.23.100.233:1490/upload |
Source: bPkG0wTVon.exe | String found in binary or memory: http://89.23.100.233:1490/upload?File |
Source: bPkG0wTVon.exe, 00000000.00000002.1495190259.0000000002A03000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://89.23.100.233:1490t- |
Source: bPkG0wTVon.exe, 00000000.00000002.1512294678.00000000702F1000.00000020.00000001.01000000.00000007.sdmp | String found in binary or memory: http://beta.visualstudio.net/net/sdk/feedback.asp |
Source: bPkG0wTVon.exe, 00000000.00000002.1495190259.0000000002872000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://icanhazip.com |
Source: bPkG0wTVon.exe, 00000000.00000002.1495190259.0000000002872000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://icanhazip.com/ |
Source: bPkG0wTVon.exe, 00000000.00000002.1495190259.0000000002872000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: Amcache.hve.24.dr | String found in binary or memory: http://upx.sf.net |
Source: tmp919C.tmp.dat.0.dr | String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: tmp919C.tmp.dat.0.dr | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: tmp919C.tmp.dat.0.dr | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: bPkG0wTVon.exe, 00000000.00000002.1499984783.0000000003A16000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.00000000039D5000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.0000000003A5C000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.00000000039FF000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.0000000003A3E000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.00000000038C1000.00000004.00000800.00020000.00000000.sdmp, tmp919D.tmp.dat.0.dr, tmp918A.tmp.dat.0.dr, tmp919F.tmp.dat.0.dr, tmp9189.tmp.dat.0.dr, tmp9188.tmp.dat.0.dr, tmp919C.tmp.dat.0.dr | String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: tmp919C.tmp.dat.0.dr | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: tmp919C.tmp.dat.0.dr | String found in binary or memory: https://gemini.google.com/app?q= |
Source: tmp919B.tmp.dat.0.dr | String found in binary or memory: https://login.live.com/ |
Source: bPkG0wTVon.exe, 00000000.00000002.1495190259.0000000002919000.00000004.00000800.00020000.00000000.sdmp, tmp919B.tmp.dat.0.dr | String found in binary or memory: https://login.live.com// |
Source: tmp919B.tmp.dat.0.dr | String found in binary or memory: https://login.live.com/https://login.live.com/ |
Source: bPkG0wTVon.exe, 00000000.00000002.1495190259.0000000002919000.00000004.00000800.00020000.00000000.sdmp, tmp919B.tmp.dat.0.dr | String found in binary or memory: https://login.live.com/v104 |
Source: bPkG0wTVon.exe, 00000000.00000002.1499984783.0000000003A16000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.00000000039D5000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.0000000003A5C000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.00000000039FF000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.0000000003A3E000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.00000000038C1000.00000004.00000800.00020000.00000000.sdmp, tmp919D.tmp.dat.0.dr, tmp918A.tmp.dat.0.dr, tmp919F.tmp.dat.0.dr, tmp9189.tmp.dat.0.dr, tmp9188.tmp.dat.0.dr, tmp919C.tmp.dat.0.dr | String found in binary or memory: https://uk.search.yahoo.com/favicon.icohttps://uk.search.yahoo.com/search |
Source: bPkG0wTVon.exe, 00000000.00000002.1499984783.0000000003A16000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.00000000039D5000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.0000000003A5C000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.00000000039FF000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.0000000003A3E000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.00000000038C1000.00000004.00000800.00020000.00000000.sdmp, tmp919D.tmp.dat.0.dr, tmp918A.tmp.dat.0.dr, tmp919F.tmp.dat.0.dr, tmp9189.tmp.dat.0.dr, tmp9188.tmp.dat.0.dr, tmp919C.tmp.dat.0.dr | String found in binary or memory: https://uk.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: bPkG0wTVon.exe, 00000000.00000002.1499984783.0000000003A16000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.00000000039D5000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.00000000038C1000.00000004.00000800.00020000.00000000.sdmp, tmp919D.tmp.dat.0.dr, tmp919F.tmp.dat.0.dr, tmp919C.tmp.dat.0.dr | String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: bPkG0wTVon.exe, 00000000.00000002.1499984783.0000000003A16000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.00000000039D5000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.00000000038C1000.00000004.00000800.00020000.00000000.sdmp, tmp919D.tmp.dat.0.dr, tmp919F.tmp.dat.0.dr, tmp919C.tmp.dat.0.dr | String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_alldp.ico |
Source: bPkG0wTVon.exe, 00000000.00000002.1499984783.0000000003A5C000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.00000000039FF000.00000004.00000800.00020000.00000000.sdmp, bPkG0wTVon.exe, 00000000.00000002.1499984783.0000000003A3E000.00000004.00000800.00020000.00000000.sdmp, tmp918A.tmp.dat.0.dr, tmp9189.tmp.dat.0.dr, tmp9188.tmp.dat.0.dr | String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_026ABAE0 | 0_2_026ABAE0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_026A9310 | 0_2_026A9310 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_026A1098 | 0_2_026A1098 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_026AB1B8 | 0_2_026AB1B8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_026A8EC8 | 0_2_026A8EC8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_026A9700 | 0_2_026A9700 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_026ABD68 | 0_2_026ABD68 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_026AD5E8 | 0_2_026AD5E8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_026ABAD1 | 0_2_026ABAD1 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_026AF3B1 | 0_2_026AF3B1 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_026AB83B | 0_2_026AB83B |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_026A1089 | 0_2_026A1089 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_026A9E40 | 0_2_026A9E40 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_026A8EB8 | 0_2_026A8EB8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_026A9F69 | 0_2_026A9F69 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_026AD5E8 | 0_2_026AD5E8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D34C50 | 0_2_04D34C50 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D3CE00 | 0_2_04D3CE00 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D36F98 | 0_2_04D36F98 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D3E733 | 0_2_04D3E733 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D320C0 | 0_2_04D320C0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D30990 | 0_2_04D30990 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D33398 | 0_2_04D33398 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D314D0 | 0_2_04D314D0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D364D8 | 0_2_04D364D8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D364C8 | 0_2_04D364C8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D31C90 | 0_2_04D31C90 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D314A3 | 0_2_04D314A3 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D34C40 | 0_2_04D34C40 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D3CDFB | 0_2_04D3CDFB |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D30EF0 | 0_2_04D30EF0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D37830 | 0_2_04D37830 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D33828 | 0_2_04D33828 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D30980 | 0_2_04D30980 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_04D3E733 | 0_2_04D3E733 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DF4553 | 0_2_05DF4553 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DFB570 | 0_2_05DFB570 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DF60D8 | 0_2_05DF60D8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DFF0D0 | 0_2_05DFF0D0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DFF880 | 0_2_05DFF880 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DFDCA0 | 0_2_05DFDCA0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DFAFD8 | 0_2_05DFAFD8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DF076F | 0_2_05DF076F |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DF4F68 | 0_2_05DF4F68 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DF6AD8 | 0_2_05DF6AD8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DFCEE0 | 0_2_05DFCEE0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DF9A88 | 0_2_05DF9A88 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DF26A0 | 0_2_05DF26A0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DF0E78 | 0_2_05DF0E78 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DFCA70 | 0_2_05DFCA70 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DF1A10 | 0_2_05DF1A10 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DF3A2F | 0_2_05DF3A2F |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DF7D48 | 0_2_05DF7D48 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DFB560 | 0_2_05DFB560 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DFDC90 | 0_2_05DFDC90 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DF8048 | 0_2_05DF8048 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DFF873 | 0_2_05DFF873 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DFF070 | 0_2_05DFF070 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DFF870 | 0_2_05DFF870 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DFA7D0 | 0_2_05DFA7D0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DF9FD0 | 0_2_05DF9FD0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DFA7C4 | 0_2_05DFA7C4 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DF9FE0 | 0_2_05DF9FE0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DF53B8 | 0_2_05DF53B8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DF2F18 | 0_2_05DF2F18 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_05DFCECF | 0_2_05DFCECF |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_08257520 | 0_2_08257520 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_08250D28 | 0_2_08250D28 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_0825BA30 | 0_2_0825BA30 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_0825B910 | 0_2_0825B910 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_0825E510 | 0_2_0825E510 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_0825D518 | 0_2_0825D518 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_0825DF60 | 0_2_0825DF60 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_08251A68 | 0_2_08251A68 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_08259C68 | 0_2_08259C68 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_0825CF68 | 0_2_0825CF68 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_0825C070 | 0_2_0825C070 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_08257F78 | 0_2_08257F78 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_08250040 | 0_2_08250040 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_08256FE0 | 0_2_08256FE0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_0825C8E8 | 0_2_0825C8E8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_0825EDC0 | 0_2_0825EDC0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_08251A30 | 0_2_08251A30 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_0825C8E8 | 0_2_0825C8E8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_0825CF57 | 0_2_0825CF57 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_0825C8A1 | 0_2_0825C8A1 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_0825EC98 | 0_2_0825EC98 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_08256FD1 | 0_2_08256FD1 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082AF49A | 0_2_082AF49A |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082AC510 | 0_2_082AC510 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082A5E68 | 0_2_082A5E68 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082A7AE0 | 0_2_082A7AE0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082A65C0 | 0_2_082A65C0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082A7640 | 0_2_082A7640 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082A9758 | 0_2_082A9758 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082A2050 | 0_2_082A2050 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082AADB8 | 0_2_082AADB8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082A4A38 | 0_2_082A4A38 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082AB00A | 0_2_082AB00A |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082A0A80 | 0_2_082A0A80 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082AEB98 | 0_2_082AEB98 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082ADE9E | 0_2_082ADE9E |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082A0A90 | 0_2_082A0A90 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082A9EE0 | 0_2_082A9EE0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082AA960 | 0_2_082AA960 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082A13F0 | 0_2_082A13F0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082A10C8 | 0_2_082A10C8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082A9748 | 0_2_082A9748 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082A0040 | 0_2_082A0040 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082A0FC7 | 0_2_082A0FC7 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082A7AD2 | 0_2_082A7AD2 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_082AA850 | 0_2_082AA850 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_08314418 | 0_2_08314418 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_08314260 | 0_2_08314260 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_08315841 | 0_2_08315841 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_08310040 | 0_2_08310040 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_08310012 | 0_2_08310012 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_08312A58 | 0_2_08312A58 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_08312A46 | 0_2_08312A46 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B3866 | 0_2_083B3866 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BB4A8 | 0_2_083BB4A8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B08F0 | 0_2_083B08F0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BF120 | 0_2_083BF120 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BFDA0 | 0_2_083BFDA0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B4D95 | 0_2_083B4D95 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B2A40 | 0_2_083B2A40 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BEAB8 | 0_2_083BEAB8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BE330 | 0_2_083BE330 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B7B10 | 0_2_083B7B10 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B5790 | 0_2_083B5790 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B33E2 | 0_2_083B33E2 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B001E | 0_2_083B001E |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BC078 | 0_2_083BC078 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BE060 | 0_2_083BE060 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B0040 | 0_2_083B0040 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BD8B0 | 0_2_083BD8B0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BCC97 | 0_2_083BCC97 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B08EA | 0_2_083B08EA |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BECD8 | 0_2_083BECD8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BCCD8 | 0_2_083BCCD8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BECC8 | 0_2_083BECC8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B18C0 | 0_2_083B18C0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B1532 | 0_2_083B1532 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B2178 | 0_2_083B2178 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B2D98 | 0_2_083B2D98 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BFD90 | 0_2_083BFD90 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B2188 | 0_2_083B2188 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BC9F8 | 0_2_083BC9F8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B2A30 | 0_2_083B2A30 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B02E0 | 0_2_083B02E0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BCB3C | 0_2_083BCB3C |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BCB28 | 0_2_083BCB28 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B1B02 | 0_2_083B1B02 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B5764 | 0_2_083B5764 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BBB40 | 0_2_083BBB40 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B8FA0 | 0_2_083B8FA0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083BDB80 | 0_2_083BDB80 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B8FE0 | 0_2_083B8FE0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B3FD0 | 0_2_083B3FD0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B8BD0 | 0_2_083B8BD0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E2458 | 0_2_085E2458 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E0040 | 0_2_085E0040 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E5A78 | 0_2_085E5A78 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E5C19 | 0_2_085E5C19 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E520B | 0_2_085E520B |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085EF4D8 | 0_2_085EF4D8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E5ED5 | 0_2_085E5ED5 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E96D0 | 0_2_085E96D0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E7AE8 | 0_2_085E7AE8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E6EE8 | 0_2_085E6EE8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085EBE88 | 0_2_085EBE88 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E5D50 | 0_2_085E5D50 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E8348 | 0_2_085E8348 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E45F0 | 0_2_085E45F0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E7590 | 0_2_085E7590 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E4E52 | 0_2_085E4E52 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E622C | 0_2_085E622C |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085EEC20 | 0_2_085EEC20 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E6EDA | 0_2_085E6EDA |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085EF4C7 | 0_2_085EF4C7 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E66E8 | 0_2_085E66E8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E9EE3 | 0_2_085E9EE3 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E189F | 0_2_085E189F |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E9ABD | 0_2_085E9ABD |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E4AA5 | 0_2_085E4AA5 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E62A0 | 0_2_085E62A0 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E755D | 0_2_085E755D |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E5742 | 0_2_085E5742 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E7B41 | 0_2_085E7B41 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E616F | 0_2_085E616F |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E1D68 | 0_2_085E1D68 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085EC708 | 0_2_085EC708 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085EAFD8 | 0_2_085EAFD8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085EEFE8 | 0_2_085EEFE8 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_085E5788 | 0_2_085E5788 |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Code function: 0_2_083B5780 | 0_2_083B5780 |
Source: unknown | Process created: C:\Users\user\Desktop\bPkG0wTVon.exe "C:\Users\user\Desktop\bPkG0wTVon.exe" | |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c tasklist | |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd" /C chcp 65001 && netsh wlan show profiles | findstr All | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\chcp.com chcp 65001 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\netsh.exe netsh wlan show profiles | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr All | |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C C:\Users\user\AppData\Local\Temp\tmp6122.tmp.bat & Del C:\Users\user\AppData\Local\Temp\tmp6122.tmp.bat | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\chcp.com chcp 65001 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\taskkill.exe TaskKill /F /IM 8592 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe Timeout /T 2 /Nobreak | |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 8592 -s 3592 | |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c tasklist | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd" /C chcp 65001 && netsh wlan show profiles | findstr All | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C C:\Users\user\AppData\Local\Temp\tmp6122.tmp.bat & Del C:\Users\user\AppData\Local\Temp\tmp6122.tmp.bat | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\chcp.com chcp 65001 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\netsh.exe netsh wlan show profiles | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr All | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\chcp.com chcp 65001 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\taskkill.exe TaskKill /F /IM 8592 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe Timeout /T 2 /Nobreak | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\chcp.com | Section loaded: ulib.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\chcp.com | Section loaded: fsutilext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ifmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mprapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasmontr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mfc42u.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: authfwcfg.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwpolicyiomgr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: firewallapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dhcpcmonitor.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dot3cfg.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dot3api.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: onex.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: eappcfg.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: eappprxy.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwcfg.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: hnetmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netshell.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netsetupapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netiohlp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshhttp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: httpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshipsec.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: activeds.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: polstore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winipsec.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: adsldpc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: adsldpc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshwfp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: p2pnetsh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: p2p.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rpcnsh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: whhelper.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wlancfg.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wlanapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wshelper.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wevtapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: peerdistsh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wcmapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rmclient.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mobilenetworking.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ktmw32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mprmsg.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\findstr.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\chcp.com | Section loaded: ulib.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\chcp.com | Section loaded: fsutilext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: | Binary string: System.Xml.ni.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: C:\Users\Malware\source\repos\ConsoleApplication2\x64\Release\ConsoleApplication2.pdb source: bPkG0wTVon.exe |
Source: | Binary string: C:\Users\Raifon\source\repos\Arcana\Arcana\bin\Release\Arcana.pdb source: bPkG0wTVon.exe |
Source: | Binary string: System.ni.pdbRSDS source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: \??\C:\Users\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\tdata source: bPkG0wTVon.exe, 00000000.00000002.1506746297.00000000076C9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Windows.Forms.ni.pdb source: bPkG0wTVon.exe, 00000000.00000002.1512294678.0000000070A0B000.00000020.00000001.01000000.00000007.sdmp, WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Management.pdbt source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Drawing.ni.pdb source: bPkG0wTVon.exe, 00000000.00000002.1524377559.0000000070BEB000.00000020.00000001.01000000.00000006.sdmp, WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Configuration.ni.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Net.Http.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Security.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Configuration.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Drawing.ni.pdbRSDS source: bPkG0wTVon.exe, 00000000.00000002.1524377559.0000000070BEB000.00000020.00000001.01000000.00000006.sdmp, WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Xml.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Xml.ni.pdbRSDS# source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Core.ni.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Windows.Forms.pdb source: bPkG0wTVon.exe, 00000000.00000002.1512294678.0000000070A0B000.00000020.00000001.01000000.00000007.sdmp, WERB95F.tmp.dmp.24.dr |
Source: | Binary string: mscorlib.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: \??\C:\Users\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\*ata source: bPkG0wTVon.exe, 00000000.00000002.1506746297.00000000076C9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.ni.pdbRSDSJ< source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Windows.Forms.ni.pdbRSDS source: bPkG0wTVon.exe, 00000000.00000002.1512294678.0000000070A0B000.00000020.00000001.01000000.00000007.sdmp, WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Net.Http.ni.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Management.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Drawing.pdb source: bPkG0wTVon.exe, 00000000.00000002.1524377559.0000000070BEB000.00000020.00000001.01000000.00000006.sdmp, WERB95F.tmp.dmp.24.dr |
Source: | Binary string: mscorlib.ni.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Management.ni.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: Arcana.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Core.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Configuration.pdbH source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: mscorlib.ni.pdbRSDS] source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.pdbp source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: C:\Users\Malware\source\repos\ConsoleApplication2\x64\Release\ConsoleApplication2.pdb" source: bPkG0wTVon.exe |
Source: | Binary string: System.Configuration.ni.pdbRSDScUN source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Net.Http.ni.pdbRSDS source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.ni.pdb source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Core.ni.pdbRSDS source: WERB95F.tmp.dmp.24.dr |
Source: | Binary string: System.Web.pdb source: WERB95F.tmp.dmp.24.dr |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bPkG0wTVon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |