Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007A445A GetFileAttributesW,FindFirstFileW,FindClose, | 0_2_007A445A |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007AC6D1 FindFirstFileW,FindClose, | 0_2_007AC6D1 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007AC75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 0_2_007AC75C |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007AEF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_007AEF95 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007AF0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_007AF0F2 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007AF3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_007AF3F3 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007A37EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_007A37EF |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007A3B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_007A3B12 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007ABCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_007ABCBC |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E8445A GetFileAttributesW,FindFirstFileW,FindClose, | 2_2_00E8445A |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E8C6D1 FindFirstFileW,FindClose, | 2_2_00E8C6D1 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E8C75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 2_2_00E8C75C |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E8EF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 2_2_00E8EF95 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E8F0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 2_2_00E8F0F2 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E8F3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 2_2_00E8F3F3 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E837EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 2_2_00E837EF |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E83B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 2_2_00E83B12 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E8BCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 2_2_00E8BCBC |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E8445A GetFileAttributesW,FindFirstFileW,FindClose, | 6_2_00E8445A |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E8C6D1 FindFirstFileW,FindClose, | 6_2_00E8C6D1 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E8C75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 6_2_00E8C75C |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E8EF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 6_2_00E8EF95 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E8F0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 6_2_00E8F0F2 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E8F3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 6_2_00E8F3F3 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E837EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 6_2_00E837EF |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E83B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 6_2_00E83B12 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E8BCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 6_2_00E8BCBC |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CCABC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 0_2_007CCABC |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EACABC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 2_2_00EACABC |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EACABC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 6_2_00EACABC |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00743633 NtdllDefWindowProc_W,KillTimer,SetTimer,RegisterClipboardFormatW,CreatePopupMenu,PostQuitMessage,SetFocus,MoveWindow, | 0_2_00743633 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CC1AC PostMessageW,GetFocus,GetDlgCtrlID,_memset,GetMenuItemInfoW,GetMenuItemCount,GetMenuItemID,GetMenuItemInfoW,GetMenuItemInfoW,CheckMenuRadioItem,NtdllDialogWndProc_W, | 0_2_007CC1AC |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CC498 GetCursorPos,TrackPopupMenuEx,GetCursorPos,NtdllDialogWndProc_W, | 0_2_007CC498 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CC57D SendMessageW,NtdllDialogWndProc_W, | 0_2_007CC57D |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CC5FE DragQueryPoint,SendMessageW,DragQueryFileW,DragQueryFileW,_wcscat,SendMessageW,SendMessageW,SendMessageW,SendMessageW,DragFinish,NtdllDialogWndProc_W, | 0_2_007CC5FE |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CC860 NtdllDialogWndProc_W, | 0_2_007CC860 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CC8BE NtdllDialogWndProc_W, | 0_2_007CC8BE |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CC88F NtdllDialogWndProc_W, | 0_2_007CC88F |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CC93E ClientToScreen,NtdllDialogWndProc_W, | 0_2_007CC93E |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CC909 NtdllDialogWndProc_W, | 0_2_007CC909 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CCA7C GetWindowLongW,NtdllDialogWndProc_W, | 0_2_007CCA7C |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CCABC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 0_2_007CCABC |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00741290 NtdllDialogWndProc_W,GetClientRect,GetCursorPos,ScreenToClient, | 0_2_00741290 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00741287 NtdllDialogWndProc_W,GetSysColor,SetBkColor,74BFC8D0,NtdllDialogWndProc_W, | 0_2_00741287 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CD3B8 NtdllDialogWndProc_W, | 0_2_007CD3B8 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CD43E GetSystemMetrics,GetSystemMetrics,MoveWindow,SendMessageW,SendMessageW,ShowWindow,InvalidateRect,NtdllDialogWndProc_W, | 0_2_007CD43E |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_0074167D NtdllDialogWndProc_W, | 0_2_0074167D |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007416DE GetParent,NtdllDialogWndProc_W, | 0_2_007416DE |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007416B5 NtdllDialogWndProc_W, | 0_2_007416B5 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CD78C NtdllDialogWndProc_W, | 0_2_007CD78C |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_0074189B NtdllDialogWndProc_W, | 0_2_0074189B |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CBC5D NtdllDialogWndProc_W,CallWindowProcW, | 0_2_007CBC5D |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CBF30 NtdllDialogWndProc_W, | 0_2_007CBF30 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007CBF8C ReleaseCapture,SetWindowTextW,SendMessageW,NtdllDialogWndProc_W, | 0_2_007CBF8C |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E23633 NtdllDefWindowProc_W,KillTimer,SetTimer,RegisterClipboardFormatW,CreatePopupMenu,PostQuitMessage,SetFocus,MoveWindow, | 2_2_00E23633 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EAC1AC PostMessageW,GetFocus,GetDlgCtrlID,_memset,GetMenuItemInfoW,GetMenuItemCount,GetMenuItemID,GetMenuItemInfoW,GetMenuItemInfoW,CheckMenuRadioItem,NtdllDialogWndProc_W, | 2_2_00EAC1AC |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EAC498 GetCursorPos,TrackPopupMenuEx,GetCursorPos,NtdllDialogWndProc_W, | 2_2_00EAC498 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EAC5FE DragQueryPoint,SendMessageW,DragQueryFileW,DragQueryFileW,_wcscat,SendMessageW,SendMessageW,SendMessageW,SendMessageW,DragFinish,NtdllDialogWndProc_W, | 2_2_00EAC5FE |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EAC57D SendMessageW,NtdllDialogWndProc_W, | 2_2_00EAC57D |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EAC8BE NtdllDialogWndProc_W, | 2_2_00EAC8BE |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EAC88F NtdllDialogWndProc_W, | 2_2_00EAC88F |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EAC860 NtdllDialogWndProc_W, | 2_2_00EAC860 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EAC93E ClientToScreen,NtdllDialogWndProc_W, | 2_2_00EAC93E |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EAC909 NtdllDialogWndProc_W, | 2_2_00EAC909 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EACABC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 2_2_00EACABC |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EACA7C GetWindowLongW,NtdllDialogWndProc_W, | 2_2_00EACA7C |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E21287 NtdllDialogWndProc_W,GetSysColor,SetBkColor,74BFC8D0,NtdllDialogWndProc_W, | 2_2_00E21287 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E21290 NtdllDialogWndProc_W,GetClientRect,GetCursorPos,ScreenToClient, | 2_2_00E21290 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EAD3B8 NtdllDialogWndProc_W, | 2_2_00EAD3B8 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EAD43E GetSystemMetrics,GetSystemMetrics,MoveWindow,SendMessageW,SendMessageW,ShowWindow,InvalidateRect,NtdllDialogWndProc_W, | 2_2_00EAD43E |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E216DE GetParent,NtdllDialogWndProc_W, | 2_2_00E216DE |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E216B5 NtdllDialogWndProc_W, | 2_2_00E216B5 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E2167D NtdllDialogWndProc_W, | 2_2_00E2167D |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EAD78C NtdllDialogWndProc_W, | 2_2_00EAD78C |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E2189B NtdllDialogWndProc_W, | 2_2_00E2189B |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EABC5D NtdllDialogWndProc_W,CallWindowProcW, | 2_2_00EABC5D |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EABF8C ReleaseCapture,SetWindowTextW,SendMessageW,NtdllDialogWndProc_W, | 2_2_00EABF8C |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EABF30 NtdllDialogWndProc_W, | 2_2_00EABF30 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E23633 NtdllDefWindowProc_W,KillTimer,SetTimer,RegisterClipboardFormatW,CreatePopupMenu,PostQuitMessage,SetFocus,MoveWindow, | 6_2_00E23633 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EAC1AC PostMessageW,GetFocus,GetDlgCtrlID,_memset,GetMenuItemInfoW,GetMenuItemCount,GetMenuItemID,GetMenuItemInfoW,GetMenuItemInfoW,CheckMenuRadioItem,NtdllDialogWndProc_W, | 6_2_00EAC1AC |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EAC498 GetCursorPos,TrackPopupMenuEx,GetCursorPos,NtdllDialogWndProc_W, | 6_2_00EAC498 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EAC5FE DragQueryPoint,SendMessageW,DragQueryFileW,DragQueryFileW,_wcscat,SendMessageW,SendMessageW,SendMessageW,SendMessageW,DragFinish,NtdllDialogWndProc_W, | 6_2_00EAC5FE |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EAC57D SendMessageW,NtdllDialogWndProc_W, | 6_2_00EAC57D |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EAC8BE NtdllDialogWndProc_W, | 6_2_00EAC8BE |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EAC88F NtdllDialogWndProc_W, | 6_2_00EAC88F |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EAC860 NtdllDialogWndProc_W, | 6_2_00EAC860 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EAC93E ClientToScreen,NtdllDialogWndProc_W, | 6_2_00EAC93E |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EAC909 NtdllDialogWndProc_W, | 6_2_00EAC909 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EACABC NtdllDialogWndProc_W,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SetCapture,ClientToScreen,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 6_2_00EACABC |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EACA7C GetWindowLongW,NtdllDialogWndProc_W, | 6_2_00EACA7C |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E21287 NtdllDialogWndProc_W,GetSysColor,SetBkColor,74BFC8D0,NtdllDialogWndProc_W, | 6_2_00E21287 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E21290 NtdllDialogWndProc_W,GetClientRect,GetCursorPos,ScreenToClient, | 6_2_00E21290 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EAD3B8 NtdllDialogWndProc_W, | 6_2_00EAD3B8 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EAD43E GetSystemMetrics,GetSystemMetrics,MoveWindow,SendMessageW,SendMessageW,ShowWindow,InvalidateRect,NtdllDialogWndProc_W, | 6_2_00EAD43E |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E216DE GetParent,NtdllDialogWndProc_W, | 6_2_00E216DE |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E216B5 NtdllDialogWndProc_W, | 6_2_00E216B5 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E2167D NtdllDialogWndProc_W, | 6_2_00E2167D |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EAD78C NtdllDialogWndProc_W, | 6_2_00EAD78C |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E2189B NtdllDialogWndProc_W, | 6_2_00E2189B |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EABC5D NtdllDialogWndProc_W,CallWindowProcW, | 6_2_00EABC5D |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EABF8C ReleaseCapture,SetWindowTextW,SendMessageW,NtdllDialogWndProc_W, | 6_2_00EABF8C |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EABF30 NtdllDialogWndProc_W, | 6_2_00EABF30 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_0074E6A0 | 0_2_0074E6A0 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_0076D975 | 0_2_0076D975 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_0074FCE0 | 0_2_0074FCE0 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007621C5 | 0_2_007621C5 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007762D2 | 0_2_007762D2 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007C03DA | 0_2_007C03DA |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_0077242E | 0_2_0077242E |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007625FA | 0_2_007625FA |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_0079E616 | 0_2_0079E616 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007566E1 | 0_2_007566E1 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_0077878F | 0_2_0077878F |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007C0857 | 0_2_007C0857 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00776844 | 0_2_00776844 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00758808 | 0_2_00758808 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007A8889 | 0_2_007A8889 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_0076CB21 | 0_2_0076CB21 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00776DB6 | 0_2_00776DB6 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00756F9E | 0_2_00756F9E |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00753030 | 0_2_00753030 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_0076F1D9 | 0_2_0076F1D9 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00763187 | 0_2_00763187 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00741287 | 0_2_00741287 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00761484 | 0_2_00761484 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00755520 | 0_2_00755520 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00767696 | 0_2_00767696 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00755760 | 0_2_00755760 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00761978 | 0_2_00761978 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00779AB5 | 0_2_00779AB5 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007C7DDB | 0_2_007C7DDB |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_0076BDA6 | 0_2_0076BDA6 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00761D90 | 0_2_00761D90 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_0074DF00 | 0_2_0074DF00 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_00753FE0 | 0_2_00753FE0 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_012FEAE0 | 0_2_012FEAE0 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E2E6A0 | 2_2_00E2E6A0 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E4D975 | 2_2_00E4D975 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E2FCE0 | 2_2_00E2FCE0 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E421C5 | 2_2_00E421C5 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E562D2 | 2_2_00E562D2 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EA03DA | 2_2_00EA03DA |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E5242E | 2_2_00E5242E |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E425FA | 2_2_00E425FA |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E366E1 | 2_2_00E366E1 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E7E616 | 2_2_00E7E616 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E5878F | 2_2_00E5878F |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E88889 | 2_2_00E88889 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E56844 | 2_2_00E56844 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EA0857 | 2_2_00EA0857 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E38808 | 2_2_00E38808 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E4CB21 | 2_2_00E4CB21 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E56DB6 | 2_2_00E56DB6 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E36F9E | 2_2_00E36F9E |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E33030 | 2_2_00E33030 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E4F1D9 | 2_2_00E4F1D9 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E43187 | 2_2_00E43187 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E21287 | 2_2_00E21287 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E41484 | 2_2_00E41484 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E35520 | 2_2_00E35520 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E47696 | 2_2_00E47696 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E35760 | 2_2_00E35760 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E41978 | 2_2_00E41978 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E59AB5 | 2_2_00E59AB5 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EA7DDB | 2_2_00EA7DDB |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E4BDA6 | 2_2_00E4BDA6 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E41D90 | 2_2_00E41D90 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E33FE0 | 2_2_00E33FE0 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E2DF00 | 2_2_00E2DF00 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_0120B128 | 2_2_0120B128 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_02854A88 | 3_2_02854A88 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_02853E70 | 3_2_02853E70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_0285AD98 | 3_2_0285AD98 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_028541B8 | 3_2_028541B8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_06337E50 | 3_2_06337E50 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_063366C0 | 3_2_063366C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_06332440 | 3_2_06332440 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_06335270 | 3_2_06335270 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_0633C270 | 3_2_0633C270 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_0633B318 | 3_2_0633B318 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_06337770 | 3_2_06337770 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_0633E478 | 3_2_0633E478 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_06330006 | 3_2_06330006 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_06330040 | 3_2_06330040 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 3_2_063359C0 | 3_2_063359C0 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E2E6A0 | 6_2_00E2E6A0 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E4D975 | 6_2_00E4D975 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E2FCE0 | 6_2_00E2FCE0 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E421C5 | 6_2_00E421C5 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E562D2 | 6_2_00E562D2 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EA03DA | 6_2_00EA03DA |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E5242E | 6_2_00E5242E |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E425FA | 6_2_00E425FA |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E366E1 | 6_2_00E366E1 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E7E616 | 6_2_00E7E616 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E5878F | 6_2_00E5878F |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E88889 | 6_2_00E88889 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E56844 | 6_2_00E56844 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EA0857 | 6_2_00EA0857 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E38808 | 6_2_00E38808 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E4CB21 | 6_2_00E4CB21 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E56DB6 | 6_2_00E56DB6 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E36F9E | 6_2_00E36F9E |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E33030 | 6_2_00E33030 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E4F1D9 | 6_2_00E4F1D9 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E43187 | 6_2_00E43187 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E21287 | 6_2_00E21287 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E41484 | 6_2_00E41484 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E35520 | 6_2_00E35520 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E47696 | 6_2_00E47696 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E35760 | 6_2_00E35760 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E41978 | 6_2_00E41978 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E59AB5 | 6_2_00E59AB5 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EA7DDB | 6_2_00EA7DDB |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E4BDA6 | 6_2_00E4BDA6 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E41D90 | 6_2_00E41D90 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E33FE0 | 6_2_00E33FE0 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E2DF00 | 6_2_00E2DF00 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_01909EE0 | 6_2_01909EE0 |
Source: 3.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 3.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 2.2.phagocytose.exe.10a0000.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.phagocytose.exe.10a0000.1.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 2.2.phagocytose.exe.10a0000.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.phagocytose.exe.10a0000.1.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 6.2.phagocytose.exe.40c0000.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 6.2.phagocytose.exe.40c0000.1.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 6.2.phagocytose.exe.40c0000.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 6.2.phagocytose.exe.40c0000.1.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 00000006.00000002.1584641137.00000000040C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 00000006.00000002.1584641137.00000000040C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 00000002.00000002.1426434556.00000000010A0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 00000002.00000002.1426434556.00000000010A0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007448D7 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 0_2_007448D7 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007C5376 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 0_2_007C5376 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E248D7 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 2_2_00E248D7 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00EA5376 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 2_2_00EA5376 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E248D7 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 6_2_00E248D7 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00EA5376 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 6_2_00EA5376 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599891 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599563 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599453 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599344 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598891 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598563 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598438 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598094 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597982 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597872 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597765 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597655 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597385 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597281 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597138 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596959 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596828 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596719 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596594 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596484 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596375 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596266 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596156 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596047 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595937 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595828 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595719 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595609 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595500 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595390 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595281 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595172 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595062 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594953 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594826 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594685 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594452 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594277 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594156 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594047 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 593937 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 593828 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599765 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599546 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599437 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599218 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598890 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598671 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598343 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598234 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598125 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598015 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597906 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597796 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597687 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597578 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597467 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597358 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597249 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597140 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597031 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596921 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596812 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596703 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596593 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596484 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596375 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596265 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596156 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596046 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595937 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595828 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595718 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595609 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595500 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595390 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595281 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595171 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595062 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594953 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594843 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594734 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594625 | Jump to behavior |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007A445A GetFileAttributesW,FindFirstFileW,FindClose, | 0_2_007A445A |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007AC6D1 FindFirstFileW,FindClose, | 0_2_007AC6D1 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007AC75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 0_2_007AC75C |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007AEF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_007AEF95 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007AF0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 0_2_007AF0F2 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007AF3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_007AF3F3 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007A37EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_007A37EF |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007A3B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 0_2_007A3B12 |
Source: C:\Users\user\Desktop\28uMwHvbTD.exe | Code function: 0_2_007ABCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 0_2_007ABCBC |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E8445A GetFileAttributesW,FindFirstFileW,FindClose, | 2_2_00E8445A |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E8C6D1 FindFirstFileW,FindClose, | 2_2_00E8C6D1 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E8C75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 2_2_00E8C75C |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E8EF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 2_2_00E8EF95 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E8F0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 2_2_00E8F0F2 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E8F3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 2_2_00E8F3F3 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E837EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 2_2_00E837EF |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E83B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 2_2_00E83B12 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 2_2_00E8BCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 2_2_00E8BCBC |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E8445A GetFileAttributesW,FindFirstFileW,FindClose, | 6_2_00E8445A |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E8C6D1 FindFirstFileW,FindClose, | 6_2_00E8C6D1 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E8C75C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 6_2_00E8C75C |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E8EF95 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 6_2_00E8EF95 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E8F0F2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 6_2_00E8F0F2 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E8F3F3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 6_2_00E8F3F3 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E837EF FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 6_2_00E837EF |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E83B12 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 6_2_00E83B12 |
Source: C:\Users\user\AppData\Local\roundup\phagocytose.exe | Code function: 6_2_00E8BCBC FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 6_2_00E8BCBC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599891 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599563 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599453 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599344 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598891 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598672 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598563 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598438 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598094 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597982 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597872 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597765 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597655 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597385 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597281 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597138 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596959 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596828 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596719 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596594 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596484 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596375 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596266 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596156 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596047 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595937 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595828 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595719 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595609 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595500 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595390 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595281 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595172 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595062 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594953 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594826 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594685 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594452 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594277 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594156 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594047 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 593937 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 593828 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599765 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599546 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599437 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599328 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599218 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598890 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598671 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598343 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598234 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598125 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 598015 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597906 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597796 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597687 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597578 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597467 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597358 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597249 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597140 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 597031 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596921 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596812 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596703 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596593 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596484 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596375 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596265 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596156 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 596046 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595937 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595828 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595718 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595609 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595500 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595390 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595281 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595171 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 595062 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594953 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594843 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594734 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Thread delayed: delay time: 594625 | Jump to behavior |