Source: VegaStealer_v2.exe, 00000000.00000003.1675111189.0000000000DC9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.di |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0 |
Source: VegaStealer_v2.exe, 00000000.00000003.1676526433.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1669197730.000000000305E000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676354121.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676045047.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1675591692.00000000031C8000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1670843784.00000000032EB000.00000004.00000020.00020000.00000000.sdmp, System.Data.SQLite.Linq.dll.0.dr, System.Data.SQLite.EF6.dll.0.dr, Newtonsoft.Json.dll.0.dr, SQLite.Interop.dll.0.dr, System.Data.SQLite.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: VegaStealer_v2.exe, 00000000.00000003.1675591692.00000000031C8000.00000004.00000020.00020000.00000000.sdmp, Newtonsoft.Json.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertCSRSA4096RootG5.crt0E |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0 |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0 |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0 |
Source: VegaStealer_v2.exe, 00000000.00000003.1676526433.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1669197730.000000000305E000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676354121.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676045047.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1670843784.00000000032EB000.00000004.00000020.00020000.00000000.sdmp, System.Data.SQLite.Linq.dll.0.dr, System.Data.SQLite.EF6.dll.0.dr, SQLite.Interop.dll.0.dr, System.Data.SQLite.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: VegaStealer_v2.exe, 00000000.00000003.1676526433.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1669197730.000000000305E000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676354121.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676045047.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1675591692.00000000031C8000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1670843784.00000000032EB000.00000004.00000020.00020000.00000000.sdmp, System.Data.SQLite.Linq.dll.0.dr, System.Data.SQLite.EF6.dll.0.dr, Newtonsoft.Json.dll.0.dr, SQLite.Interop.dll.0.dr, System.Data.SQLite.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: VegaStealer_v2.exe, 00000000.00000003.1676526433.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1669197730.000000000305E000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676354121.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676045047.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1675591692.00000000031C8000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1670843784.00000000032EB000.00000004.00000020.00020000.00000000.sdmp, System.Data.SQLite.Linq.dll.0.dr, System.Data.SQLite.EF6.dll.0.dr, Newtonsoft.Json.dll.0.dr, SQLite.Interop.dll.0.dr, System.Data.SQLite.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: VegaStealer_v2.exe, 00000000.00000003.1675591692.00000000031C8000.00000004.00000020.00020000.00000000.sdmp, Newtonsoft.Json.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA2.crt0 |
Source: VegaStealer_v2.exe, 00000000.00000003.1670423287.00000000031CB000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1668465146.0000000002D59000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crPl3.d |
Source: VegaStealer_v2.exe, 00000000.00000003.1676099242.0000000000DCA000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676554027.0000000000DCC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.d |
Source: VegaStealer_v2.exe, 00000000.00000003.1675743529.0000000000DC9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert |
Source: VegaStealer_v2.exe, 00000000.00000003.1670423287.00000000031CB000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1668465146.0000000002D59000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.cPom/D |
Source: VegaStealer_v2.exe, 00000000.00000003.1676554027.0000000000DCC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com |
Source: VegaStealer_v2.exe, 00000000.00000003.1676099242.0000000000DCA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/ |
Source: VegaStealer_v2.exe, 00000000.00000003.1676526433.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1669197730.000000000305E000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676354121.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676045047.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1675591692.00000000031C8000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1670843784.00000000032EB000.00000004.00000020.00020000.00000000.sdmp, System.Data.SQLite.Linq.dll.0.dr, System.Data.SQLite.EF6.dll.0.dr, Newtonsoft.Json.dll.0.dr, SQLite.Interop.dll.0.dr, System.Data.SQLite.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P |
Source: VegaStealer_v2.exe, 00000000.00000003.1675591692.00000000031C8000.00000004.00000020.00020000.00000000.sdmp, Newtonsoft.Json.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertCSRSA4096RootG5.crl0 |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0 |
Source: VegaStealer_v2.exe, 00000000.00000003.1676526433.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1669197730.000000000305E000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676354121.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676045047.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1670843784.00000000032EB000.00000004.00000020.00020000.00000000.sdmp, System.Data.SQLite.Linq.dll.0.dr, System.Data.SQLite.EF6.dll.0.dr, SQLite.Interop.dll.0.dr, System.Data.SQLite.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: VegaStealer_v2.exe, 00000000.00000003.1676526433.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1669197730.000000000305E000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676354121.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676045047.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1675591692.00000000031C8000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1670843784.00000000032EB000.00000004.00000020.00020000.00000000.sdmp, System.Data.SQLite.Linq.dll.0.dr, System.Data.SQLite.EF6.dll.0.dr, Newtonsoft.Json.dll.0.dr, SQLite.Interop.dll.0.dr, System.Data.SQLite.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: System.Data.SQLite.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07 |
Source: VegaStealer_v2.exe, 00000000.00000003.1675591692.00000000031C8000.00000004.00000020.00020000.00000000.sdmp, Newtonsoft.Json.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0F |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02 |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0: |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0 |
Source: VegaStealer_v2.exe, 00000000.00000003.1676526433.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1669197730.000000000305E000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676354121.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676045047.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1670843784.00000000032EB000.00000004.00000020.00020000.00000000.sdmp, System.Data.SQLite.Linq.dll.0.dr, System.Data.SQLite.EF6.dll.0.dr, SQLite.Interop.dll.0.dr, System.Data.SQLite.dll.0.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0= |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K |
Source: VegaStealer_v2.exe, 00000000.00000003.1675591692.00000000031C8000.00000004.00000020.00020000.00000000.sdmp, Newtonsoft.Json.dll.0.dr | String found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0= |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0 |
Source: VegaStealer_v2.exe, 00000000.00000003.1673193963.00000000031C7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://go.micr |
Source: VegaStealer_v2.exe, 00000000.00000003.1673193963.00000000031C7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://go.micro |
Source: VegaStealer_v2.exe, 00000000.00000003.1673193963.00000000031C7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://go.micros |
Source: VegaStealer_v2.exe, 00000000.00000003.1673193963.00000000031C7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://go.microso |
Source: VegaStealer_v2.exe, 00000000.00000003.1673193963.00000000031C7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://go.microsof |
Source: VegaStealer_v2.exe, 00000000.00000003.1673193963.00000000031C7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://go.microsoft |
Source: VegaStealer_v2.exe, 00000000.00000003.1673193963.00000000031C7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://go.microsoft. |
Source: v2.exe, 00000001.00000002.1766165520.0000000002F36000.00000004.00000800.00020000.00000000.sdmp, v2.exe, 00000001.00000002.1766165520.0000000002DFA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com |
Source: VegaStealer_v2.exe, 00000000.00000003.1676781668.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, v2.exe, 00000001.00000002.1766165520.0000000002DFA000.00000004.00000800.00020000.00000000.sdmp, v2.exe, 00000001.00000000.1677351963.0000000000822000.00000002.00000001.01000000.00000005.sdmp, v2.exe.0.dr | String found in binary or memory: http://ip-api.com/json/?fields=61439 |
Source: v2.exe, 00000001.00000002.1766165520.0000000002F36000.00000004.00000800.00020000.00000000.sdmp, v2.exe, 00000001.00000002.1766165520.0000000002DFA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com/json/?fields=61439d |
Source: v2.exe, 00000001.00000002.1766165520.0000000002F36000.00000004.00000800.00020000.00000000.sdmp, v2.exe, 00000001.00000002.1766165520.0000000002DFA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.comd |
Source: Newtonsoft.Json.dll.0.dr | String found in binary or memory: http://james.newtonking.com/projects/json |
Source: v2.exe, 00000001.00000002.1773344472.00000000076A1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ns.adobe.0/ |
Source: VegaStealer_v2.exe, 00000000.00000003.1675111189.0000000000DC9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.c |
Source: VegaStealer_v2.exe, 00000000.00000003.1676526433.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1669197730.000000000305E000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676354121.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676045047.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1670843784.00000000032EB000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676554027.0000000000DCC000.00000004.00000020.00020000.00000000.sdmp, System.Data.SQLite.Linq.dll.0.dr, System.Data.SQLite.EF6.dll.0.dr, SQLite.Interop.dll.0.dr, System.Data.SQLite.dll.0.dr | String found in binary or memory: http://ocsp.digicert.com0 |
Source: VegaStealer_v2.exe, 00000000.00000003.1676526433.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1669197730.000000000305E000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676099242.0000000000DCA000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676354121.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676045047.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1675591692.00000000031C8000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1670843784.00000000032EB000.00000004.00000020.00020000.00000000.sdmp, System.Data.SQLite.Linq.dll.0.dr, System.Data.SQLite.EF6.dll.0.dr, Newtonsoft.Json.dll.0.dr, SQLite.Interop.dll.0.dr, System.Data.SQLite.dll.0.dr | String found in binary or memory: http://ocsp.digicert.com0A |
Source: VegaStealer_v2.exe, 00000000.00000003.1676526433.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1669197730.000000000305E000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676354121.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676045047.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1675591692.00000000031C8000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1670843784.00000000032EB000.00000004.00000020.00020000.00000000.sdmp, System.Data.SQLite.Linq.dll.0.dr, System.Data.SQLite.EF6.dll.0.dr, Newtonsoft.Json.dll.0.dr, SQLite.Interop.dll.0.dr, System.Data.SQLite.dll.0.dr, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://ocsp.digicert.com0C |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://ocsp.digicert.com0H |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://ocsp.digicert.com0I |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1675591692.00000000031C8000.00000004.00000020.00020000.00000000.sdmp, Newtonsoft.Json.dll.0.dr, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://ocsp.digicert.com0O |
Source: VegaStealer_v2.exe, 00000000.00000003.1676526433.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1669197730.000000000305E000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676354121.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676045047.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1675591692.00000000031C8000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1670843784.00000000032EB000.00000004.00000020.00020000.00000000.sdmp, System.Data.SQLite.Linq.dll.0.dr, System.Data.SQLite.EF6.dll.0.dr, Newtonsoft.Json.dll.0.dr, SQLite.Interop.dll.0.dr, System.Data.SQLite.dll.0.dr | String found in binary or memory: http://ocsp.digicert.com0X |
Source: v2.exe, 00000001.00000002.1766165520.0000000002BC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: VegaStealer_v2.exe, 00000000.00000003.1676526433.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1669197730.000000000305E000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676354121.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676045047.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1675591692.00000000031C8000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1670843784.00000000032EB000.00000004.00000020.00020000.00000000.sdmp, System.Data.SQLite.Linq.dll.0.dr, System.Data.SQLite.EF6.dll.0.dr, Newtonsoft.Json.dll.0.dr, SQLite.Interop.dll.0.dr, System.Data.SQLite.dll.0.dr, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: http://www.digicert.com/ssl-cps-repository.htm0 |
Source: v2.exe, 00000001.00000002.1768833657.00000000041C8000.00000004.00000800.00020000.00000000.sdmp, tmp6165.tmp.dat.1.dr, tmp60C4.tmp.dat.1.dr | String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: v2.exe, 00000001.00000002.1766165520.0000000002C8B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://answers.netlify.com/t/support-guide-i-ve-deployed-my-site-but-i-still-see-page-not-found/125 |
Source: v2.exe, 00000001.00000002.1766165520.0000000002BC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot |
Source: v2.exe, 00000001.00000002.1766165520.0000000002BC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.vimeworld.ru/user/name/ |
Source: v2.exe, 00000001.00000002.1768833657.00000000041C8000.00000004.00000800.00020000.00000000.sdmp, tmp6165.tmp.dat.1.dr, tmp60C4.tmp.dat.1.dr | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: v2.exe, 00000001.00000002.1768833657.00000000041C8000.00000004.00000800.00020000.00000000.sdmp, tmp6165.tmp.dat.1.dr, tmp60C4.tmp.dat.1.dr | String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: v2.exe, 00000001.00000002.1768833657.00000000041C8000.00000004.00000800.00020000.00000000.sdmp, tmp6165.tmp.dat.1.dr, tmp60C4.tmp.dat.1.dr | String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: v2.exe, 00000001.00000002.1768833657.00000000041C8000.00000004.00000800.00020000.00000000.sdmp, tmp6165.tmp.dat.1.dr, tmp60C4.tmp.dat.1.dr | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: v2.exe, 00000001.00000002.1768833657.00000000041C8000.00000004.00000800.00020000.00000000.sdmp, tmp6165.tmp.dat.1.dr, tmp60C4.tmp.dat.1.dr | String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: v2.exe, 00000001.00000002.1768833657.00000000041C8000.00000004.00000800.00020000.00000000.sdmp, tmp6165.tmp.dat.1.dr, tmp60C4.tmp.dat.1.dr | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: v2.exe, 00000001.00000002.1766165520.0000000002BC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://freegeoip.app |
Source: v2.exe, 00000001.00000002.1766165520.0000000002BC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://freegeoip.app/xml/ |
Source: VegaStealer_v2.exe, 00000000.00000003.1676781668.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, v2.exe, 00000001.00000000.1677351963.0000000000822000.00000002.00000001.01000000.00000005.sdmp, v2.exe.0.dr | String found in binary or memory: https://freegeoip.app/xml/9https://api.telegram.org/botGhttps://api.vimeworld.ru/user/name/1-------- |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: https://github.com/novotnyllc/bc-csharp |
Source: v2.exe, 00000001.00000002.1766165520.0000000002C24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ipbase.com |
Source: v2.exe, 00000001.00000002.1766165520.0000000002C20000.00000004.00000800.00020000.00000000.sdmp, v2.exe, 00000001.00000002.1766165520.0000000002C24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ipbase.com/xml/ |
Source: VegaStealer_v2.exe, 00000000.00000003.1676781668.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, v2.exe, 00000001.00000000.1677351963.0000000000822000.00000002.00000001.01000000.00000005.sdmp, v2.exe.0.dr | String found in binary or memory: https://steamcommunity.com/profiles/ASOFTWARE |
Source: tmp6196.tmp.tmpdb.1.dr | String found in binary or memory: https://support.mozilla.org |
Source: tmp6196.tmp.tmpdb.1.dr | String found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br |
Source: v2.exe, 00000001.00000002.1768833657.0000000003CAF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://support.mozilla.org/products/firefo |
Source: tmp6196.tmp.tmpdb.1.dr | String found in binary or memory: https://support.mozilla.org/products/firefoxgro.allizom.troppus.zvXrErQ5GYDF |
Source: v2.exe, 00000001.00000002.1768833657.0000000003C8F000.00000004.00000800.00020000.00000000.sdmp, tmp6115.tmp.dat.1.dr, tmp6135.tmp.dat.1.dr, History.txt.1.dr | String found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016 |
Source: tmp6115.tmp.dat.1.dr, tmp6135.tmp.dat.1.dr | String found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016Examples |
Source: v2.exe, 00000001.00000002.1768833657.0000000003C8F000.00000004.00000800.00020000.00000000.sdmp, tmp6115.tmp.dat.1.dr, tmp6135.tmp.dat.1.dr, History.txt.1.dr | String found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17 |
Source: tmp6115.tmp.dat.1.dr, tmp6135.tmp.dat.1.dr | String found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17Install |
Source: System.Data.SQLite.dll.0.dr | String found in binary or memory: https://system.data.sqlite.org/ |
Source: VegaStealer_v2.exe, 00000000.00000003.1676045047.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, v2.exe, 00000001.00000002.1772408987.0000000006754000.00000002.00000001.01000000.00000008.sdmp, System.Data.SQLite.dll.0.dr | String found in binary or memory: https://system.data.sqlite.org/X |
Source: VegaStealer_v2.exe, 00000000.00000003.1676781668.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, v2.exe, 00000001.00000002.1766165520.0000000002BC1000.00000004.00000800.00020000.00000000.sdmp, v2.exe, 00000001.00000002.1766165520.0000000002E0C000.00000004.00000800.00020000.00000000.sdmp, v2.exe, 00000001.00000002.1766165520.0000000002DFA000.00000004.00000800.00020000.00000000.sdmp, v2.exe, 00000001.00000000.1677351963.0000000000822000.00000002.00000001.01000000.00000005.sdmp, v2.exe.0.dr, Information.txt.1.dr | String found in binary or memory: https://t.me/VegaStealer_bot |
Source: VegaStealer_v2.exe, 00000000.00000003.1676781668.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, v2.exe, 00000001.00000000.1677351963.0000000000822000.00000002.00000001.01000000.00000005.sdmp, v2.exe.0.dr | String found in binary or memory: https://t.me/VegaStealer_bot-/sendDocument?chat_id= |
Source: System.Data.SQLite.dll.0.dr | String found in binary or memory: https://urn.to/r/sds_see |
Source: VegaStealer_v2.exe, 00000000.00000003.1672426233.00000000033D9000.00000004.00000020.00020000.00000000.sdmp, BouncyCastle.Crypto.dll.0.dr | String found in binary or memory: https://www.digicert.com/CPS0 |
Source: v2.exe, 00000001.00000002.1768833657.00000000041C8000.00000004.00000800.00020000.00000000.sdmp, tmp6165.tmp.dat.1.dr, tmp60C4.tmp.dat.1.dr | String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: v2.exe, 00000001.00000002.1768833657.00000000041C8000.00000004.00000800.00020000.00000000.sdmp, tmp6165.tmp.dat.1.dr, tmp60C4.tmp.dat.1.dr | String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: tmp6196.tmp.tmpdb.1.dr | String found in binary or memory: https://www.mozilla.org |
Source: tmp6196.tmp.tmpdb.1.dr | String found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.VsJpOAWrHqB2 |
Source: tmp6196.tmp.tmpdb.1.dr | String found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.n0g9CLHwD9nR |
Source: History.txt0.1.dr | String found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/) |
Source: v2.exe, 00000001.00000002.1768833657.0000000004244000.00000004.00000800.00020000.00000000.sdmp, v2.exe, 00000001.00000002.1768833657.0000000003CAF000.00000004.00000800.00020000.00000000.sdmp, tmp60D4.tmp.tmpdb.1.dr, tmp6196.tmp.tmpdb.1.dr | String found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/Firefox |
Source: tmp6196.tmp.tmpdb.1.dr | String found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig |
Source: v2.exe, 00000001.00000002.1768833657.0000000004244000.00000004.00000800.00020000.00000000.sdmp, v2.exe, 00000001.00000002.1768833657.0000000003CAF000.00000004.00000800.00020000.00000000.sdmp, tmp60D4.tmp.tmpdb.1.dr, tmp6196.tmp.tmpdb.1.dr | String found in binary or memory: https://www.mozilla.org/privacy/firefox/gro.allizom.www. |
Source: VegaStealer_v2.exe, 00000000.00000003.1675591692.00000000031C8000.00000004.00000020.00020000.00000000.sdmp, Newtonsoft.Json.dll.0.dr | String found in binary or memory: https://www.newtonsoft.com/json |
Source: Newtonsoft.Json.dll.0.dr | String found in binary or memory: https://www.newtonsoft.com/jsonschema |
Source: v2.exe, v2.exe, 00000001.00000002.1771673921.0000000006012000.00000002.00000001.01000000.00000007.sdmp, Newtonsoft.Json.dll.0.dr | String found in binary or memory: https://www.nuget.org/packages/Newtonsoft.Json.Bson |
Source: VegaStealer_v2.exe, 00000000.00000003.1669197730.0000000002EAC000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1670843784.00000000032EB000.00000004.00000020.00020000.00000000.sdmp, v2.exe, 00000001.00000002.1776158717.000000006C03C000.00000002.00000001.01000000.00000009.sdmp, SQLite.Interop.dll.0.dr | String found in binary or memory: https://www.sqlite.org/copyright.html2 |
Source: VegaStealer_v2.exe, 00000000.00000003.1676099242.0000000000DCA000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676554027.0000000000DCC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.sqlite.org/lang |
Source: VegaStealer_v2.exe, 00000000.00000003.1676526433.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676354121.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, System.Data.SQLite.Linq.dll.0.dr, System.Data.SQLite.EF6.dll.0.dr | String found in binary or memory: https://www.sqlite.org/lang_aggfunc.html |
Source: VegaStealer_v2.exe, 00000000.00000003.1676099242.0000000000DCA000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676554027.0000000000DCC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.sqlite.org/lang_c |
Source: VegaStealer_v2.exe, 00000000.00000003.1676526433.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, VegaStealer_v2.exe, 00000000.00000003.1676354121.00000000031C1000.00000004.00000020.00020000.00000000.sdmp, System.Data.SQLite.Linq.dll.0.dr, System.Data.SQLite.EF6.dll.0.dr | String found in binary or memory: https://www.sqlite.org/lang_corefunc.html |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_06012974 | 1_2_06012974 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_066F6B97 | 1_2_066F6B97 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF96160 | 1_2_6BF96160 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BFA5D80 | 1_2_6BFA5D80 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF6EBD0 | 1_2_6BF6EBD0 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF84B50 | 1_2_6BF84B50 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF02AD0 | 1_2_6BF02AD0 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF76AA0 | 1_2_6BF76AA0 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF56A70 | 1_2_6BF56A70 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF16930 | 1_2_6BF16930 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF86900 | 1_2_6BF86900 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF14870 | 1_2_6BF14870 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF70810 | 1_2_6BF70810 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF94800 | 1_2_6BF94800 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BEF8FEE | 1_2_6BEF8FEE |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF00E77 | 1_2_6BF00E77 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF36DD0 | 1_2_6BF36DD0 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BFA0D90 | 1_2_6BFA0D90 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BFE6C50 | 1_2_6BFE6C50 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF3E350 | 1_2_6BF3E350 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF66260 | 1_2_6BF66260 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF0024A | 1_2_6BF0024A |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF861D0 | 1_2_6BF861D0 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF0C1C0 | 1_2_6BF0C1C0 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BFD2100 | 1_2_6BFD2100 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BFAC0C0 | 1_2_6BFAC0C0 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF0079B | 1_2_6BF0079B |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF146F0 | 1_2_6BF146F0 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF986A0 | 1_2_6BF986A0 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF2A5F0 | 1_2_6BF2A5F0 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BEF4589 | 1_2_6BEF4589 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF20550 | 1_2_6BF20550 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF924C0 | 1_2_6BF924C0 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF0A4A0 | 1_2_6BF0A4A0 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BFC04A0 | 1_2_6BFC04A0 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF02491 | 1_2_6BF02491 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF72400 | 1_2_6BF72400 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BFD1B80 | 1_2_6BFD1B80 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF21B10 | 1_2_6BF21B10 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BFE3A90 | 1_2_6BFE3A90 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF9DA80 | 1_2_6BF9DA80 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF9FA50 | 1_2_6BF9FA50 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BFCDA50 | 1_2_6BFCDA50 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF5D800 | 1_2_6BF5D800 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF33FA0 | 1_2_6BF33FA0 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BFCFE40 | 1_2_6BFCFE40 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF27D70 | 1_2_6BF27D70 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BEFFCF9 | 1_2_6BEFFCF9 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF57C90 | 1_2_6BF57C90 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF9F3A0 | 1_2_6BF9F3A0 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BF07340 | 1_2_6BF07340 |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Code function: 1_2_6BFB1340 | 1_2_6BFB1340 |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VegaStealer_v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 599860 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 599735 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 599610 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 599485 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 599315 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 599188 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 599063 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 598914 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 598813 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 598704 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 598579 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 598454 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 598329 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 598204 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 598079 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 597954 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 597829 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 597704 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 597579 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 597454 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 597329 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 597204 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 597079 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 596954 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 596829 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 596704 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 596579 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 596454 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 596329 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 596204 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 596079 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 595907 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 595782 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 595657 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 595532 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 595407 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 595282 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 595157 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 595048 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 594923 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 594798 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 594673 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 594548 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -30437127721620741s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -599860s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -599735s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -599610s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -599485s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -599315s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -599188s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -599063s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -598914s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -598813s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -598704s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -598579s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -598454s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -598329s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -598204s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -598079s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -597954s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -597829s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -597704s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -597579s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -597454s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -597329s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -597204s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -597079s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -596954s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -596829s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -596704s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -596579s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -596454s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -596329s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -596204s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -596079s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -595907s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -595782s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -595657s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -595532s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -595407s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -595282s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -595157s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -595048s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -594923s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -594798s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -594673s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3844 | Thread sleep time: -594548s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 3616 | Thread sleep time: -30000s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe TID: 2260 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 599860 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 599735 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 599610 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 599485 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 599315 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 599188 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 599063 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 598914 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 598813 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 598704 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 598579 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 598454 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 598329 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 598204 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 598079 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 597954 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 597829 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 597704 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 597579 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 597454 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 597329 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 597204 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 597079 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 596954 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 596829 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 596704 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 596579 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 596454 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 596329 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 596204 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 596079 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 595907 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 595782 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 595657 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 595532 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 595407 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 595282 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 595157 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 595048 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 594923 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 594798 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 594673 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 594548 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\v2.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |