Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00482870 FindFirstFileW,FindFirstFileW,FindClose,FindFirstFileW,FindFirstFileW,FindClose, |
0_2_00482870 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00458060 GetFullPathNameW,GetFullPathNameW,GetFullPathNameW,GetFileAttributesW,GetFileAttributesW,GetFileAttributesW,FindFirstFileW,GetLastError,GetTickCount,PeekMessageW,GetTickCount,MoveFileW,DeleteFileW,MoveFileW,CopyFileW,GetLastError,FindNextFileW,FindClose, |
0_2_00458060 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00421100 FindFirstFileW,FindFirstFileW,GetTickCount,PeekMessageW,GetTickCount,FindNextFileW,FindClose,FindFirstFileW,FindFirstFileW,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,GetTickCount,FindNextFileW,FindClose, |
0_2_00421100 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004213A0 FindFirstFileW,GetLastError,FindClose,FileTimeToLocalFileTime,FileTimeToSystemTime, |
0_2_004213A0 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00421700 CreateFileW,GetFileSizeEx,CloseHandle,FindFirstFileW,GetLastError,FindClose, |
0_2_00421700 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00421850 GetFileAttributesW,FindFirstFileW,FindNextFileW,FindNextFileW,FindNextFileW,FindClose,FindClose, |
0_2_00421850 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004ADB1B FindFirstFileExW, |
0_2_004ADB1B |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0044AC00 FindFirstFileW,FindNextFileW,FindNextFileW,FindNextFileW,FindNextFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose, |
0_2_0044AC00 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004570C0 InternetOpenW,InternetOpenUrlW,InternetOpenUrlW,GetLastError,InternetOpenUrlW,GetLastError,InternetCloseHandle,CreateFileW,GetLastError,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,InternetReadFile,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,WriteFile,InternetReadFile,GetLastError,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,CloseHandle,GetLastError,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,CloseHandle,InternetReadFileExA,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,WriteFile,InternetReadFileExA,GetLastError,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,CloseHandle,DeleteFileW, |
0_2_004570C0 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004067A0 GlobalAlloc,GlobalLock,GlobalFree,EmptyClipboard,GlobalUnlock,CloseClipboard,GlobalUnlock,GlobalUnlock,GlobalFree,GlobalUnlock,CloseClipboard,SetClipboardData,GlobalUnlock,CloseClipboard, |
0_2_004067A0 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00484C60 EmptyClipboard,GlobalAlloc,GlobalLock,GlobalUnlock,SetClipboardData,GlobalUnlock,CloseClipboard,GlobalFree,GlobalUnlock,CloseClipboard,GlobalUnlock,CloseClipboard, |
0_2_00484C60 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004281B0 GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetDC,GetDC,GetLastError,DestroyIcon,DeleteObject,CreateCompatibleDC,GetIconInfo,DeleteObject,DeleteObject,DeleteObject,GetDC,CreateCompatibleDC,GetIconInfo,GetObjectW,CreateCompatibleBitmap,SelectObject,CreateSolidBrush,FillRect,DeleteObject,DrawIconEx,SelectObject,DeleteObject,DeleteObject,DeleteDC,ReleaseDC,DestroyIcon,CreateCompatibleDC,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,GetLastError,ReleaseDC,DeleteObject,SelectObject,DeleteDC,DeleteObject, |
0_2_004281B0 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004191D8 GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,AttachThreadInput,BlockInput,GetTickCount, |
0_2_004191D8 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004191EC GetTickCount,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,AttachThreadInput,BlockInput,GetTickCount, |
0_2_004191EC |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00418248 CloseHandle,CloseHandle,CreateMutexW,GetLastError,GetWindowThreadProcessId,GetWindowThreadProcessId,GetModuleHandleW,GetProcAddress,SendMessageTimeoutW,AttachThreadInput,GetKeyboardLayout,__alloca_probe_16,BlockInput,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,PostMessageW,PostMessageW,GetTickCount,PeekMessageW,GetTickCount,PostMessageW,PostMessageW,PostMessageW,PostMessageW,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetForegroundWindow,GetWindowThreadProcessId,AttachThreadInput,BlockInput,GetTickCount,GetForegroundWindow,GetWindowThreadProcessId, |
0_2_00418248 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0041828D CloseHandle,CloseHandle,CreateMutexW,GetLastError,GetWindowThreadProcessId,GetWindowThreadProcessId,GetModuleHandleW,GetProcAddress,AttachThreadInput,GetKeyboardLayout,__alloca_probe_16,BlockInput,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,AttachThreadInput,BlockInput,GetTickCount, |
0_2_0041828D |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00418296 CloseHandle,CloseHandle,CreateMutexW,GetLastError,GetWindowThreadProcessId,GetWindowThreadProcessId,GetModuleHandleW,GetProcAddress,AttachThreadInput,GetKeyboardLayout,__alloca_probe_16,BlockInput,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,AttachThreadInput,BlockInput,GetTickCount, |
0_2_00418296 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0041829F CloseHandle,CloseHandle,CreateMutexW,GetLastError,GetWindowThreadProcessId,GetWindowThreadProcessId,GetModuleHandleW,GetProcAddress,AttachThreadInput,GetKeyboardLayout,__alloca_probe_16,BlockInput,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,AttachThreadInput,BlockInput,GetTickCount, |
0_2_0041829F |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004182A8 CloseHandle,CloseHandle,CreateMutexW,GetLastError,GetWindowThreadProcessId,GetWindowThreadProcessId,GetModuleHandleW,GetProcAddress,AttachThreadInput,GetKeyboardLayout,__alloca_probe_16,BlockInput,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,AttachThreadInput,BlockInput,GetTickCount, |
0_2_004182A8 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00418356 GetWindowThreadProcessId,GetWindowThreadProcessId,GetModuleHandleW,GetProcAddress,AttachThreadInput,GetKeyboardLayout,__alloca_probe_16,BlockInput,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,AttachThreadInput,BlockInput,GetTickCount, |
0_2_00418356 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004183BF GetWindowThreadProcessId,GetWindowThreadProcessId,GetModuleHandleW,GetProcAddress,AttachThreadInput,GetKeyboardLayout,__alloca_probe_16,BlockInput,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,AttachThreadInput,BlockInput,GetTickCount, |
0_2_004183BF |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00418495 GetTickCount,GetCurrentThreadId,GetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetGUIThreadInfo,GetWindowThreadProcessId,GetKeyboardLayout,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,__alloca_probe_16,BlockInput,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,AttachThreadInput,BlockInput,GetTickCount, |
0_2_00418495 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004186B2 __alloca_probe_16,BlockInput,GetTickCount,GetTickCount,PeekMessageW,GetTickCount,GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,AttachThreadInput,BlockInput,GetTickCount, |
0_2_004186B2 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00450960 GetKeyState,GetKeyState,GetKeyState,GetForegroundWindow,GetWindowThreadProcessId,GetKeyState, |
0_2_00450960 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0044D360 GetFileAttributesW,__alloca_probe_16,__alloca_probe_16,__alloca_probe_16,CreateProcessWithLogonW,GetLastError,CreateProcessW,CloseHandle,CloseHandle,GetLastError,__alloca_probe_16,SetCurrentDirectoryW,SetCurrentDirectoryW,GetFileAttributesW,SetCurrentDirectoryW,SetCurrentDirectoryW,ShellExecuteExW,CloseHandle,CloseHandle,SetCurrentDirectoryW,GetLastError,FormatMessageW, |
0_2_0044D360 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004B6062 |
0_2_004B6062 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0043D0A0 |
0_2_0043D0A0 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0045D170 |
0_2_0045D170 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0048B100 |
0_2_0048B100 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00481110 |
0_2_00481110 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004271F0 |
0_2_004271F0 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004281B0 |
0_2_004281B0 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00418248 |
0_2_00418248 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0042B274 |
0_2_0042B274 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004A2344 |
0_2_004A2344 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0042D320 |
0_2_0042D320 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004B03F6 |
0_2_004B03F6 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004415F0 |
0_2_004415F0 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00465640 |
0_2_00465640 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00401623 |
0_2_00401623 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0048B6DE |
0_2_0048B6DE |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0048E6AC |
0_2_0048E6AC |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00425700 |
0_2_00425700 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0047D7A0 |
0_2_0047D7A0 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004698E0 |
0_2_004698E0 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004A69CE |
0_2_004A69CE |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004A8A00 |
0_2_004A8A00 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00454AD0 |
0_2_00454AD0 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0042BAE0 |
0_2_0042BAE0 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00427BC0 |
0_2_00427BC0 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00499B90 |
0_2_00499B90 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0043EBB0 |
0_2_0043EBB0 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0040EC50 |
0_2_0040EC50 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004B4C6A |
0_2_004B4C6A |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0045FC20 |
0_2_0045FC20 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00411D80 |
0_2_00411D80 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_00423E00 |
0_2_00423E00 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004A1FE5 |
0_2_004A1FE5 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_004B5FA8 |
0_2_004B5FA8 |
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: String function: 0049BFA0 appears 34 times |
|
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: String function: 0049CA21 appears 32 times |
|
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: String function: 0040E150 appears 40 times |
|
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: String function: 004B57A0 appears 35 times |
|
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: String function: 0049EE91 appears 159 times |
|
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: String function: 0040C830 appears 102 times |
|
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: String function: 0049F012 appears 48 times |
|
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: String function: 0040D460 appears 54 times |
|
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: String function: 00481800 appears 37 times |
|
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: String function: 0040D660 appears 65 times |
|
Source: C:\Users\user\Desktop\Login_msifar.txt.exe |
Code function: 0_2_0044D360 GetFileAttributesW,__alloca_probe_16,__alloca_probe_16,__alloca_probe_16,CreateProcessWithLogonW,GetLastError,CreateProcessW,CloseHandle,CloseHandle,GetLastError,__alloca_probe_16,SetCurrentDirectoryW,SetCurrentDirectoryW,GetFileAttributesW,SetCurrentDirectoryW,SetCurrentDirectoryW,ShellExecuteExW,CloseHandle,CloseHandle,SetCurrentDirectoryW,GetLastError,FormatMessageW, |
0_2_0044D360 |