Source: LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://https://https/:://websocketpp.processorGeneric |
Source: LightSpoofer.exe, 00000000.00000003.1735642826.000002CCA2974000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1991756112.000002CCA2952000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1898472222.000002CCA2996000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: LightSpoofer.exe, 00000000.00000003.1986371452.000002CCA0E92000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1986371452.000002CCA0EAB000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1735330542.000002CCA0E8D000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1736758764.000002CCA0EAB000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1730804959.000002CCA0EAB000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000002.4131654747.000002CCA0E8D000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000002.4131654747.000002CCA0EAB000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1736758764.000002CCA0E8D000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://api.myip.com/ |
Source: LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://api.myip.com/Russia |
Source: LightSpoofer.exe, 00000000.00000003.1730701144.000002CCA2ACB000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://bridge.lga1.admarketplace.net/ctp?version=16.0.0&key=1696332238301000001.2&ci=1696332238417. |
Source: LightSpoofer.exe, 00000000.00000003.1730701144.000002CCA2ACB000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://bridge.lga1.ap01.net/ctp?version=16.0.0&key=1696332238301000001.1&ci=1696332238417.12791&cta |
Source: LightSpoofer.exe, 00000000.00000003.1735642826.000002CCA2974000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1991756112.000002CCA2952000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1898472222.000002CCA2996000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: LightSpoofer.exe, 00000000.00000003.1735642826.000002CCA2974000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1991756112.000002CCA2952000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1898472222.000002CCA2996000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: LightSpoofer.exe, 00000000.00000003.1735642826.000002CCA2974000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1991756112.000002CCA2952000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1898472222.000002CCA2996000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: LightSpoofer.exe, 00000000.00000003.1730701144.000002CCA2ACB000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://contile-images.services.mozilla.com/0TegrVVRalreHILhR2WvtD_CFzj13HCDcLqqpvXSOuY.10862.jpg |
Source: LightSpoofer.exe, 00000000.00000003.1730701144.000002CCA2ACB000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg |
Source: LightSpoofer.exe, 00000000.00000003.1735642826.000002CCA2974000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1991756112.000002CCA2952000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1898472222.000002CCA2996000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: LightSpoofer.exe, 00000000.00000003.1735642826.000002CCA2974000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1991756112.000002CCA2952000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1898472222.000002CCA2996000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: LightSpoofer.exe, 00000000.00000003.1735642826.000002CCA2974000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1991756112.000002CCA2952000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1898472222.000002CCA2996000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: LightSpoofer.exe, LightSpoofer.exe, 00000000.00000002.4136772725.00007FF661CED000.00000002.00000001.01000000.00000003.sdmp |
String found in binary or memory: https://github.com/ocornut/imgui/blob/master/docs/FAQ.md#qa-usage |
Source: LightSpoofer.exe, 00000000.00000002.4136772725.00007FF661CED000.00000002.00000001.01000000.00000003.sdmp |
String found in binary or memory: https://github.com/ocornut/imgui/blob/master/docs/FAQ.md#qa-usage(Hold |
Source: LightSpoofer.exe, 00000000.00000003.1771653224.000002CCA29CB000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://go.mic |
Source: LightSpoofer.exe, 00000000.00000003.1730701144.000002CCA2ACB000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4QqmfZfYfQfafZbXfpbWfpbX7ReNxR3UIG8zInwYIFIVs9eYi |
Source: LightSpoofer.exe, 00000000.00000003.1771653224.000002CCA29CB000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1759955726.000002CCA2854000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1838201876.000002CCA2A22000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1869770850.000002CCA2854000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1869770850.000002CCA2808000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1821874330.000002CCA2808000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1815010928.000002CCA2854000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1730997226.000002CCA29E3000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000002.4131769985.000002CCA2810000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.2306930819.000002CCA2854000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1825870311.000002CCA2808000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1939921750.000002CCA2854000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1787880746.000002CCA2808000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1762675022.000002CCA2809000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1920670025.000002CCA2808000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1751522050.000002CCA2854000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1805800803.000002CCA2854000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.2304535540.000002CCA2809000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1894061014.000002CCA2808000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1759955726.000002CCA2809000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1825870311.000002CCA2854000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016 |
Source: LightSpoofer.exe, 00000000.00000003.1877956950.000002CCA29A8000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000002.4131769985.000002CCA29FD000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016Examples |
Source: LightSpoofer.exe, 00000000.00000003.1771653224.000002CCA29CB000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1986371452.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1838201876.000002CCA2A22000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1771653224.000002CCA299F000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1833082467.000002CCA299F000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1735642826.000002CCA299F000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1730997226.000002CCA29E3000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000002.4131654747.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1844370263.000002CCA299F000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.3433586346.000002CCA299F000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1906545811.000002CCA299F000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1735642826.000002CCA29E4000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1787880746.000002CCA299F000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1739398693.000002CCA299F000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1730997226.000002CCA299F000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1760758571.000002CCA299F000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1741934343.000002CCA299F000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1779684507.000002CCA299F000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1877956950.000002CCA299F000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1912255604.000002CCA299F000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1859449285.000002CCA299F000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17 |
Source: LightSpoofer.exe, 00000000.00000003.1877956950.000002CCA29A8000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000002.4131769985.000002CCA29FD000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17Install |
Source: LightSpoofer.exe, 00000000.00000003.1986371452.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000002.4131654747.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1735330542.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1730804959.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1736758764.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17kies |
Source: LightSpoofer.exe, 00000000.00000003.1986371452.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000002.4131654747.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1735330542.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1730804959.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1736758764.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17okiesyB |
Source: LightSpoofer.exe, 00000000.00000003.1730701144.000002CCA2ACB000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_7548d4575af019e4c148ccf1a78112802e66a0816a72fc94 |
Source: LightSpoofer.exe, 00000000.00000003.1735642826.000002CCA2974000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1991756112.000002CCA2952000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1898472222.000002CCA2996000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: LightSpoofer.exe, 00000000.00000003.1730701144.000002CCA2ACB000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.expedia.com/?locale=en_US&siteid=1&semcid=US.UB.ADMARKETPLACE.GT-C-EN.HOTEL&SEMDTL=a1219 |
Source: LightSpoofer.exe, 00000000.00000003.1735642826.000002CCA2974000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1991756112.000002CCA2952000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1898472222.000002CCA2996000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Code function: 0_2_00007FF661CB8A74 |
0_2_00007FF661CB8A74 |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Code function: 0_2_00007FF661CDC1D0 |
0_2_00007FF661CDC1D0 |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Code function: 0_2_00007FF661CD251C |
0_2_00007FF661CD251C |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Code function: 0_2_00007FF661CDACE4 |
0_2_00007FF661CDACE4 |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Code function: 0_2_00007FF661CD2C90 |
0_2_00007FF661CD2C90 |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Code function: 0_2_00007FF661CB6D94 |
0_2_00007FF661CB6D94 |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Code function: 0_2_00007FF661CBA110 |
0_2_00007FF661CBA110 |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Code function: 0_2_00007FF661CCA920 |
0_2_00007FF661CCA920 |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Code function: 0_2_00007FF661CB28BC |
0_2_00007FF661CB28BC |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Code function: 0_2_00007FF661CB8028 |
0_2_00007FF661CB8028 |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Code function: 0_2_00007FF661CA3F78 |
0_2_00007FF661CA3F78 |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Code function: 0_2_00007FF661CB97AC |
0_2_00007FF661CB97AC |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: d3d9.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: msvcp140.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: vcruntime140_1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: vcruntime140.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: vcruntime140.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: vcruntime140_1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: vcruntime140.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: d3d10warp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: resourcepolicyclient.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: dxcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: xinput1_4.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: devobj.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: inputhost.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: LightSpoofer.exe, 00000000.00000002.4136809939.00007FF661FAC000.00000004.00000001.01000000.00000003.sdmp |
Binary or memory string: SOFTWARE\VMware, Inc.\VMware ToolsNOPQRSTUVWXYZABCDEFGHIJKLMnopqrstuvwxyzabcdefghijklm0123456789+/LoadLibraryA |
Source: LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp |
Binary or memory string: vboxtray |
Source: LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp |
Binary or memory string: vmtoolsdvboxserviceu |
Source: LightSpoofer.exe, 00000000.00000002.4136809939.00007FF661FAC000.00000004.00000001.01000000.00000003.sdmp |
Binary or memory string: Kernel32.dllKernel32.dll\\.\VBoxMiniRdrDN |
Source: LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp |
Binary or memory string: qemu-ga |
Source: LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp |
Binary or memory string: vboxtrayx64dbgh |
Source: LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp |
Binary or memory string: vboxservice |
Source: LightSpoofer.exe, 00000000.00000002.4136809939.00007FF661FAC000.00000004.00000001.01000000.00000003.sdmp |
Binary or memory string: SOFTWARE\VMware, Inc.\VMware Tools |
Source: LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp |
Binary or memory string: vmwareuser |
Source: LightSpoofer.exe, 00000000.00000002.4136809939.00007FF661FAC000.00000004.00000001.01000000.00000003.sdmp |
Binary or memory string: \\.\VBoxMiniRdrDN |
Source: LightSpoofer.exe, 00000000.00000003.1986371452.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000002.4131654747.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000002.4130559701.000002CCA0999000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1735330542.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1730804959.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp, LightSpoofer.exe, 00000000.00000003.1736758764.000002CCA0ED4000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW |
Source: LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp |
Binary or memory string: wiresharkvmwareuseri |
Source: LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp |
Binary or memory string: vmtoolsd |
Source: LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp |
Binary or memory string: vmwaretray |
Source: LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp |
Binary or memory string: qemu-gaVGAuthServicevmwaretrayv |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
NtProtectVirtualMemory: Direct from: 0x7FF662309FA1 |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
NtQueryInformationProcess: Direct from: 0x7FF66216B64E |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
NtQueryInformationProcess: Direct from: 0x7FF6622D8A27 |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
NtProtectVirtualMemory: Direct from: 0x7FF6621A84F7 |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
NtProtectVirtualMemory: Direct from: 0x7FF662171C72 |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
NtQuerySystemInformation: Direct from: 0x7FF662171C51 |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
NtSetInformationProcess: Direct from: 0x7FF662309991 |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
NtProtectVirtualMemory: Direct from: 0x7FF662306851 |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
NtQuerySystemInformation: Direct from: 0x7FF6621C842C |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
NtQuerySystemInformation: Direct from: 0x7FF66230F56F |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
NtProtectVirtualMemory: Direct from: 0x7FF6621D1F6B |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
NtQuerySystemInformation: Direct from: 0x7FF6621B996E |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
NtSetInformationThread: Direct from: 0x7FF6621A8523 |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
NtQueryInformationProcess: Direct from: 0x7FF6622DBDC8 |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
NtProtectVirtualMemory: Direct from: 0x7FF66248A3B6 |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
NtProtectVirtualMemory: Direct from: 0x7FF662171F10 |
Jump to behavior |
Source: LightSpoofer.exe, 00000000.00000003.2184192889.000002CCA09F8000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: Electrum |
Source: LightSpoofer.exe, 00000000.00000003.1986371452.000002CCA0EAB000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: C:\Users\user\AppData\Roaming\ElectronCash\wallets |
Source: LightSpoofer.exe, 00000000.00000003.2184192889.000002CCA09F8000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: \Jaxx |
Source: LightSpoofer.exe, 00000000.00000002.4131031186.000002CCA0A2C000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: ming\Exodus\exodus.wallet |
Source: LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp |
String found in binary or memory: \Daedalus Mainnet\Ethereum\Guarda\Local Storage\leveldb\Zcash |
Source: LightSpoofer.exe, 00000000.00000002.4131031186.000002CCA0A2C000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: ming\Exodus\exodus.wallet |
Source: LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp |
String found in binary or memory: Ethereum |
Source: LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp |
String found in binary or memory: \Coinomi\Coinomi\wallets |
Source: LightSpoofer.exe, 00000000.00000002.4131199142.000002CCA0A40000.00000040.00001000.00020000.00000000.sdmp |
String found in binary or memory: \Ethereum\keystore |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\key4.db |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\Cookies |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\History |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\prefs.js |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\cookies.sqlite |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\z6bny8rn.default\prefs.js |
Jump to behavior |
Source: C:\Users\user\Desktop\LightSpoofer.exe |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data |
Jump to behavior |