Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: 0_2_004F7529 |
0_2_004F7529 |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: 0_2_004F19DF |
0_2_004F19DF |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: 0_2_004FB464 |
0_2_004FB464 |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: 0_2_004FBC1E |
0_2_004FBC1E |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: 0_2_004FB836 |
0_2_004FB836 |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: 0_2_004FAC31 |
0_2_004FAC31 |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: 0_2_004FB0C6 |
0_2_004FB0C6 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: 3_2_0037B836 |
3_2_0037B836 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: 3_2_0037AC31 |
3_2_0037AC31 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: 3_2_0037BC1E |
3_2_0037BC1E |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: 3_2_0037B464 |
3_2_0037B464 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: 3_2_0037B0C6 |
3_2_0037B0C6 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: 3_2_00377529 |
3_2_00377529 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: 3_2_003719DF |
3_2_003719DF |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SystemHandler |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SystemHandler |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SystemHandler |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SystemHandler |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe TID: 1996 |
Thread sleep count: 596 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe TID: 1996 |
Thread sleep time: -29800000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe TID: 5568 |
Thread sleep count: 5050 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe TID: 5568 |
Thread sleep time: -4646000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe TID: 5568 |
Thread sleep count: 3903 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe TID: 5568 |
Thread sleep time: -3590760s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
API call chain: ExitProcess graph end node |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
API call chain: ExitProcess graph end node |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
API call chain: ExitProcess graph end node |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
API call chain: ExitProcess graph end node |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
API call chain: ExitProcess graph end node |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: 0_2_004FCA46 SetUnhandledExceptionFilter, |
0_2_004FCA46 |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: 0_2_004F8A8F IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
0_2_004F8A8F |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: 0_2_005002B8 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_005002B8 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: 3_2_0037CA46 SetUnhandledExceptionFilter, |
3_2_0037CA46 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: 3_2_003802B8 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
3_2_003802B8 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: 3_2_00378A8F IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
3_2_00378A8F |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,_strlen,GetLocaleInfoA,_strlen,_TestDefaultLanguage, |
0_2_00501453 |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,__alloca_probe_16,_malloc,GetLocaleInfoW,WideCharToMultiByte,__freea, |
0_2_00502CBB |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat, |
0_2_00502D95 |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
0_2_0050125C |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: GetLocaleInfoA,_LocaleUpdate::_LocaleUpdate,___ascii_strnicmp,__tolower_l,__tolower_l, |
0_2_00502A77 |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage, |
0_2_00501624 |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA, |
0_2_005016E4 |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA, |
0_2_00501351 |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: _strlen,_GetPrimaryLen,EnumSystemLocalesA, |
0_2_0050174B |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__invoke_watson,GetLocaleInfoW,GetLocaleInfoW,__calloc_crt,GetLocaleInfoW,_free,GetLocaleInfoW, |
0_2_00501BCC |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: GetLocaleInfoW,_GetPrimaryLen,_strlen, |
0_2_005013F8 |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: __getptd,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoA,_strcpy_s,__invoke_watson,GetLocaleInfoA,GetLocaleInfoA,__itow_s, |
0_2_00501787 |
Source: C:\Users\user\Desktop\7zba89tklZ.exe |
Code function: GetLocaleInfoA, |
0_2_00502BAC |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,_strlen,GetLocaleInfoA,_strlen,_TestDefaultLanguage, |
3_2_00381453 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,__alloca_probe_16,_malloc,GetLocaleInfoW,WideCharToMultiByte,__freea, |
3_2_00382CBB |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat, |
3_2_00382D95 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage, |
3_2_00381624 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: GetLocaleInfoA,_LocaleUpdate::_LocaleUpdate,___ascii_strnicmp,__tolower_l,__tolower_l, |
3_2_00382A77 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
3_2_0038125C |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA, |
3_2_003816E4 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA, |
3_2_00381351 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: _strlen,_GetPrimaryLen,EnumSystemLocalesA, |
3_2_0038174B |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: GetLocaleInfoA, |
3_2_00382BAC |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: __getptd,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoA,_strcpy_s,__invoke_watson,GetLocaleInfoA,GetLocaleInfoA,__itow_s, |
3_2_00381787 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: GetLocaleInfoW,_GetPrimaryLen,_strlen, |
3_2_003813F8 |
Source: C:\Users\user\AppData\Local\Microsoft\svcapp.exe |
Code function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__invoke_watson,GetLocaleInfoW,GetLocaleInfoW,__calloc_crt,GetLocaleInfoW,_free,GetLocaleInfoW, |
3_2_00381BCC |