Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0073445A GetFileAttributesW,FindFirstFileW,FindClose, | 0_2_0073445A |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0073C6D1 FindFirstFileW,FindClose, | 0_2_0073C6D1 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0073C75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 0_2_0073C75C |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0073EF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_0073EF95 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0073F0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_0073F0F2 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0073F3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_0073F3F3 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_007337EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_007337EF |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_00733B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_00733B12 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0073BCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_0073BCBC |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003B445A GetFileAttributesW,FindFirstFileW,FindClose, | 1_2_003B445A |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003BC6D1 FindFirstFileW,FindClose, | 1_2_003BC6D1 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003BC75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 1_2_003BC75C |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003BEF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 1_2_003BEF95 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003BF0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 1_2_003BF0F2 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003BF3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 1_2_003BF3F3 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003B37EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 1_2_003B37EF |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003B3B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 1_2_003B3B12 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003BBCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 1_2_003BBCBC |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003B445A GetFileAttributesW,FindFirstFileW,FindClose, | 4_2_003B445A |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003BC6D1 FindFirstFileW,FindClose, | 4_2_003BC6D1 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003BC75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 4_2_003BC75C |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003BEF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 4_2_003BEF95 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003BF0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 4_2_003BF0F2 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003BF3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 4_2_003BF3F3 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003B37EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 4_2_003B37EF |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003B3B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 4_2_003B3B12 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003BBCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 4_2_003BBCBC |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075CABC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 0_2_0075CABC |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DCABC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 1_2_003DCABC |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DCABC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 4_2_003DCABC |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006D3633 NtdllDefWindowProc_W,KillTimer,SetTimer,RegisterClipboardFormatW,CreatePopupMenu,PostQuitMessage,SetFocus,MoveWindow, | 0_2_006D3633 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075C1AC PostMessageW,GetFocus,GetDlgCtrlID,_memset,GetMenuItemInfoW,GetMenuItemCount,GetMenuItemID,GetMenuItemInfoW,GetMenuItemInfoW,CheckMenuRadioItem,NtdllDialogWndProc_W, | 0_2_0075C1AC |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075C498 GetCursorPos,TrackPopupMenuEx,GetCursorPos,NtdllDialogWndProc_W, | 0_2_0075C498 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075C57D SendMessageW,NtdllDialogWndProc_W, | 0_2_0075C57D |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075C5FE DragQueryPoint,SendMessageW,DragQueryFileW,DragQueryFileW,_wcscat,SendMessageW,SendMessageW,SendMessageW,SendMessageW,DragFinish,NtdllDialogWndProc_W, | 0_2_0075C5FE |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075C860 NtdllDialogWndProc_W, | 0_2_0075C860 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075C8BE NtdllDialogWndProc_W, | 0_2_0075C8BE |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075C88F NtdllDialogWndProc_W, | 0_2_0075C88F |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075C93E ClientToScreen,NtdllDialogWndProc_W, | 0_2_0075C93E |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075C909 NtdllDialogWndProc_W, | 0_2_0075C909 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075CA7C GetWindowLongW,NtdllDialogWndProc_W, | 0_2_0075CA7C |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075CABC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 0_2_0075CABC |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006D1287 NtdllDialogWndProc_W,GetSysColor,SetBkColor,745EC8D0,NtdllDialogWndProc_W, | 0_2_006D1287 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006D1290 NtdllDialogWndProc_W,GetClientRect,GetCursorPos,ScreenToClient, | 0_2_006D1290 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075D3B8 NtdllDialogWndProc_W, | 0_2_0075D3B8 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075D43E GetSystemMetrics,GetSystemMetrics,MoveWindow,SendMessageW,SendMessageW,ShowWindow,InvalidateRect,NtdllDialogWndProc_W, | 0_2_0075D43E |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006D167D NtdllDialogWndProc_W, | 0_2_006D167D |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006D16DE GetParent,NtdllDialogWndProc_W, | 0_2_006D16DE |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006D16B5 NtdllDialogWndProc_W, | 0_2_006D16B5 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075D78C NtdllDialogWndProc_W, | 0_2_0075D78C |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006D189B NtdllDialogWndProc_W, | 0_2_006D189B |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075BC5D NtdllDialogWndProc_W,CallWindowProcW, | 0_2_0075BC5D |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075BF30 NtdllDialogWndProc_W, | 0_2_0075BF30 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0075BF8C ReleaseCapture,ChrCmpIA,SetWindowTextW,SendMessageW,NtdllDialogWndProc_W, | 0_2_0075BF8C |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00353633 NtdllDefWindowProc_W,KillTimer,SetTimer,RegisterClipboardFormatW,CreatePopupMenu,PostQuitMessage,SetFocus,MoveWindow, | 1_2_00353633 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DC1AC PostMessageW,GetFocus,GetDlgCtrlID,_memset,GetMenuItemInfoW,GetMenuItemCount,GetMenuItemID,GetMenuItemInfoW,GetMenuItemInfoW,CheckMenuRadioItem,NtdllDialogWndProc_W, | 1_2_003DC1AC |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DC498 GetCursorPos,TrackPopupMenuEx,GetCursorPos,NtdllDialogWndProc_W, | 1_2_003DC498 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DC57D SendMessageW,NtdllDialogWndProc_W, | 1_2_003DC57D |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DC5FE DragQueryPoint,SendMessageW,DragQueryFileW,DragQueryFileW,_wcscat,SendMessageW,SendMessageW,SendMessageW,SendMessageW,DragFinish,NtdllDialogWndProc_W, | 1_2_003DC5FE |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DC860 NtdllDialogWndProc_W, | 1_2_003DC860 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DC8BE NtdllDialogWndProc_W, | 1_2_003DC8BE |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DC88F NtdllDialogWndProc_W, | 1_2_003DC88F |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DC93E ClientToScreen,NtdllDialogWndProc_W, | 1_2_003DC93E |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DC909 NtdllDialogWndProc_W, | 1_2_003DC909 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DCA7C GetWindowLongW,NtdllDialogWndProc_W, | 1_2_003DCA7C |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DCABC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 1_2_003DCABC |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00351290 NtdllDialogWndProc_W,GetClientRect,GetCursorPos,ScreenToClient, | 1_2_00351290 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00351287 NtdllDialogWndProc_W,GetSysColor,SetBkColor,745EC8D0,NtdllDialogWndProc_W, | 1_2_00351287 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DD3B8 NtdllDialogWndProc_W, | 1_2_003DD3B8 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DD43E GetSystemMetrics,GetSystemMetrics,MoveWindow,SendMessageW,SendMessageW,ShowWindow,InvalidateRect,NtdllDialogWndProc_W, | 1_2_003DD43E |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_0035167D NtdllDialogWndProc_W, | 1_2_0035167D |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003516B5 NtdllDialogWndProc_W, | 1_2_003516B5 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003516DE GetParent,NtdllDialogWndProc_W, | 1_2_003516DE |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DD78C NtdllDialogWndProc_W, | 1_2_003DD78C |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_0035189B NtdllDialogWndProc_W, | 1_2_0035189B |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DBC5D NtdllDialogWndProc_W,CallWindowProcW, | 1_2_003DBC5D |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DBF30 NtdllDialogWndProc_W, | 1_2_003DBF30 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003DBF8C ReleaseCapture,ChrCmpIA,SetWindowTextW,SendMessageW,NtdllDialogWndProc_W, | 1_2_003DBF8C |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00353633 NtdllDefWindowProc_W,KillTimer,SetTimer,RegisterClipboardFormatW,CreatePopupMenu,PostQuitMessage,SetFocus,MoveWindow, | 4_2_00353633 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DC1AC PostMessageW,GetFocus,GetDlgCtrlID,_memset,GetMenuItemInfoW,GetMenuItemCount,GetMenuItemID,GetMenuItemInfoW,GetMenuItemInfoW,CheckMenuRadioItem,NtdllDialogWndProc_W, | 4_2_003DC1AC |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DC498 GetCursorPos,TrackPopupMenuEx,GetCursorPos,NtdllDialogWndProc_W, | 4_2_003DC498 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DC57D SendMessageW,NtdllDialogWndProc_W, | 4_2_003DC57D |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DC5FE DragQueryPoint,SendMessageW,DragQueryFileW,DragQueryFileW,_wcscat,SendMessageW,SendMessageW,SendMessageW,SendMessageW,DragFinish,NtdllDialogWndProc_W, | 4_2_003DC5FE |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DC860 NtdllDialogWndProc_W, | 4_2_003DC860 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DC8BE NtdllDialogWndProc_W, | 4_2_003DC8BE |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DC88F NtdllDialogWndProc_W, | 4_2_003DC88F |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DC93E ClientToScreen,NtdllDialogWndProc_W, | 4_2_003DC93E |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DC909 NtdllDialogWndProc_W, | 4_2_003DC909 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DCA7C GetWindowLongW,NtdllDialogWndProc_W, | 4_2_003DCA7C |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DCABC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 4_2_003DCABC |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00351290 NtdllDialogWndProc_W,GetClientRect,GetCursorPos,ScreenToClient, | 4_2_00351290 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00351287 NtdllDialogWndProc_W,GetSysColor,SetBkColor,745EC8D0,NtdllDialogWndProc_W, | 4_2_00351287 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DD3B8 NtdllDialogWndProc_W, | 4_2_003DD3B8 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DD43E GetSystemMetrics,GetSystemMetrics,MoveWindow,SendMessageW,SendMessageW,ShowWindow,InvalidateRect,NtdllDialogWndProc_W, | 4_2_003DD43E |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_0035167D NtdllDialogWndProc_W, | 4_2_0035167D |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003516B5 NtdllDialogWndProc_W, | 4_2_003516B5 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003516DE GetParent,NtdllDialogWndProc_W, | 4_2_003516DE |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DD78C NtdllDialogWndProc_W, | 4_2_003DD78C |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_0035189B NtdllDialogWndProc_W, | 4_2_0035189B |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DBC5D NtdllDialogWndProc_W,CallWindowProcW, | 4_2_003DBC5D |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DBF30 NtdllDialogWndProc_W, | 4_2_003DBF30 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003DBF8C ReleaseCapture,ChrCmpIA,SetWindowTextW,SendMessageW,NtdllDialogWndProc_W, | 4_2_003DBF8C |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006DE6A0 | 0_2_006DE6A0 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006FD975 | 0_2_006FD975 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006DFCE0 | 0_2_006DFCE0 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006F21C5 | 0_2_006F21C5 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_007062D2 | 0_2_007062D2 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_007503DA | 0_2_007503DA |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0070242E | 0_2_0070242E |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006F25FA | 0_2_006F25FA |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0072E616 | 0_2_0072E616 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006E66E1 | 0_2_006E66E1 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0070878F | 0_2_0070878F |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_00750857 | 0_2_00750857 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_00706844 | 0_2_00706844 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006E8808 | 0_2_006E8808 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_00738889 | 0_2_00738889 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006FCB21 | 0_2_006FCB21 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_00706DB6 | 0_2_00706DB6 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006E6F9E | 0_2_006E6F9E |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006E3030 | 0_2_006E3030 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006FF1D9 | 0_2_006FF1D9 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006F3187 | 0_2_006F3187 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006D1287 | 0_2_006D1287 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006F1484 | 0_2_006F1484 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006E5520 | 0_2_006E5520 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006F7696 | 0_2_006F7696 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006E5760 | 0_2_006E5760 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006F1978 | 0_2_006F1978 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_00709AB5 | 0_2_00709AB5 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_00757DDB | 0_2_00757DDB |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006FBDA6 | 0_2_006FBDA6 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006F1D90 | 0_2_006F1D90 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006DDF00 | 0_2_006DDF00 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006E3FE0 | 0_2_006E3FE0 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_01207C80 | 0_2_01207C80 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_0035E6A0 | 1_2_0035E6A0 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_0037D975 | 1_2_0037D975 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_0035FCE0 | 1_2_0035FCE0 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003721C5 | 1_2_003721C5 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003862D2 | 1_2_003862D2 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003D03DA | 1_2_003D03DA |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_0038242E | 1_2_0038242E |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003725FA | 1_2_003725FA |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003AE616 | 1_2_003AE616 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003666E1 | 1_2_003666E1 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_0038878F | 1_2_0038878F |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00368808 | 1_2_00368808 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003D0857 | 1_2_003D0857 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00386844 | 1_2_00386844 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003B8889 | 1_2_003B8889 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_0037CB21 | 1_2_0037CB21 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00386DB6 | 1_2_00386DB6 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00366F9E | 1_2_00366F9E |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00363030 | 1_2_00363030 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00373187 | 1_2_00373187 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_0037F1D9 | 1_2_0037F1D9 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00351287 | 1_2_00351287 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00371484 | 1_2_00371484 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00365520 | 1_2_00365520 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00377696 | 1_2_00377696 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00365760 | 1_2_00365760 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00371978 | 1_2_00371978 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00389AB5 | 1_2_00389AB5 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_0037BDA6 | 1_2_0037BDA6 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00371D90 | 1_2_00371D90 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003D7DDB | 1_2_003D7DDB |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_0035DF00 | 1_2_0035DF00 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00363FE0 | 1_2_00363FE0 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_00F66B88 | 1_2_00F66B88 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_03124A88 | 2_2_03124A88 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_03123E70 | 2_2_03123E70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0312AD98 | 2_2_0312AD98 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_031241B8 | 2_2_031241B8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06B466C0 | 2_2_06B466C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06B47E50 | 2_2_06B47E50 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06B42440 | 2_2_06B42440 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06B45270 | 2_2_06B45270 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06B4C270 | 2_2_06B4C270 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06B4B318 | 2_2_06B4B318 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06B47770 | 2_2_06B47770 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06B4E478 | 2_2_06B4E478 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06B40040 | 2_2_06B40040 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06B459C0 | 2_2_06B459C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06B40033 | 2_2_06B40033 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_06B40013 | 2_2_06B40013 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_0035E6A0 | 4_2_0035E6A0 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_0037D975 | 4_2_0037D975 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_0035FCE0 | 4_2_0035FCE0 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003721C5 | 4_2_003721C5 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003862D2 | 4_2_003862D2 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003D03DA | 4_2_003D03DA |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_0038242E | 4_2_0038242E |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003725FA | 4_2_003725FA |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003AE616 | 4_2_003AE616 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003666E1 | 4_2_003666E1 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_0038878F | 4_2_0038878F |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00368808 | 4_2_00368808 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003D0857 | 4_2_003D0857 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00386844 | 4_2_00386844 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003B8889 | 4_2_003B8889 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_0037CB21 | 4_2_0037CB21 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00386DB6 | 4_2_00386DB6 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00366F9E | 4_2_00366F9E |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00363030 | 4_2_00363030 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00373187 | 4_2_00373187 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_0037F1D9 | 4_2_0037F1D9 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00351287 | 4_2_00351287 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00371484 | 4_2_00371484 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00365520 | 4_2_00365520 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00377696 | 4_2_00377696 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00365760 | 4_2_00365760 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00371978 | 4_2_00371978 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00389AB5 | 4_2_00389AB5 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_0037BDA6 | 4_2_0037BDA6 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00371D90 | 4_2_00371D90 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003D7DDB | 4_2_003D7DDB |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_0035DF00 | 4_2_0035DF00 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00363FE0 | 4_2_00363FE0 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_00D814C8 | 4_2_00D814C8 |
Source: 2.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 1.2.tapestrylike.exe.dc0000.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 1.2.tapestrylike.exe.dc0000.1.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 4.2.tapestrylike.exe.32c0000.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 4.2.tapestrylike.exe.32c0000.1.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 1.2.tapestrylike.exe.dc0000.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 1.2.tapestrylike.exe.dc0000.1.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 4.2.tapestrylike.exe.32c0000.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 4.2.tapestrylike.exe.32c0000.1.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 00000004.00000002.1857662810.00000000032C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 00000004.00000002.1857662810.00000000032C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 00000001.00000002.1717320804.0000000000DC0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 00000001.00000002.1717320804.0000000000DC0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: C:\Users\user\Desktop\987656789009800.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_006D48D7 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 0_2_006D48D7 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_00755376 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 0_2_00755376 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003548D7 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 1_2_003548D7 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003D5376 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 1_2_003D5376 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003548D7 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 4_2_003548D7 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003D5376 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 4_2_003D5376 |
Source: C:\Users\user\Desktop\987656789009800.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599891 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599766 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599437 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598878 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598762 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598448 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598327 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598217 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598108 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597886 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597437 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597094 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596983 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596875 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596766 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596437 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596108 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595889 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595695 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595484 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595355 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595250 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595141 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595031 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594922 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594812 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594703 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594578 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594469 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594359 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594250 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594137 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599765 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599437 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599218 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598890 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598344 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598234 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598125 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598015 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597906 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597796 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597687 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597578 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597469 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597357 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597250 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597139 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597031 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596922 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596812 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596703 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596594 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596484 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596375 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596266 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596156 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596047 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595937 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595828 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595719 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595607 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595500 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595390 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595281 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595172 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595062 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594952 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594844 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594734 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594625 | Jump to behavior |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0073445A GetFileAttributesW,FindFirstFileW,FindClose, | 0_2_0073445A |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0073C6D1 FindFirstFileW,FindClose, | 0_2_0073C6D1 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0073C75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 0_2_0073C75C |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0073EF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_0073EF95 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0073F0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_0073F0F2 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0073F3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_0073F3F3 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_007337EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_007337EF |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_00733B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_00733B12 |
Source: C:\Users\user\Desktop\987656789009800.exe | Code function: 0_2_0073BCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_0073BCBC |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003B445A GetFileAttributesW,FindFirstFileW,FindClose, | 1_2_003B445A |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003BC6D1 FindFirstFileW,FindClose, | 1_2_003BC6D1 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003BC75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 1_2_003BC75C |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003BEF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 1_2_003BEF95 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003BF0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 1_2_003BF0F2 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003BF3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 1_2_003BF3F3 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003B37EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 1_2_003B37EF |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003B3B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 1_2_003B3B12 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 1_2_003BBCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 1_2_003BBCBC |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003B445A GetFileAttributesW,FindFirstFileW,FindClose, | 4_2_003B445A |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003BC6D1 FindFirstFileW,FindClose, | 4_2_003BC6D1 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003BC75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 4_2_003BC75C |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003BEF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 4_2_003BEF95 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003BF0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 4_2_003BF0F2 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003BF3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 4_2_003BF3F3 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003B37EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 4_2_003B37EF |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003B3B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 4_2_003B3B12 |
Source: C:\Users\user\AppData\Local\interseminating\tapestrylike.exe | Code function: 4_2_003BBCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 4_2_003BBCBC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599891 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599766 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599437 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598878 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598762 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598448 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598327 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598217 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598108 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597886 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597437 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597094 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596983 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596875 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596766 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596437 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596108 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595889 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595695 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595484 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595355 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595250 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595141 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595031 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594922 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594812 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594703 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594578 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594469 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594359 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594250 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594137 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599765 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599437 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599218 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598890 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598344 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598234 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598125 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598015 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597906 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597796 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597687 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597578 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597469 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597357 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597250 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597139 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597031 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596922 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596812 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596703 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596594 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596484 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596375 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596266 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596156 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596047 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595937 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595828 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595719 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595607 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595500 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595390 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595281 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595172 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595062 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594952 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594844 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594734 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594625 | Jump to behavior |