Source: qqnal04.exe, 00000000.00000002.2106933727.000002902BB52000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://api.telegram.org |
Source: qqnal04.exe | String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0 |
Source: qqnal04.exe | String found in binary or memory: http://crl.globalsign.com/gsextendcodesignsha2g3.crl0 |
Source: qqnal04.exe | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0b |
Source: qqnal04.exe | String found in binary or memory: http://crl.globalsign.net/root-r3.crl0 |
Source: qqnal04.exe, 00000000.00000002.2106933727.000002902BC7D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://get.geojs.io |
Source: qqnal04.exe | String found in binary or memory: http://ocsp2.globalsign.com/gsextendcodesignsha2g30U |
Source: qqnal04.exe | String found in binary or memory: http://ocsp2.globalsign.com/gstimestampingsha2g20 |
Source: qqnal04.exe | String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: qqnal04.exe, 00000000.00000002.2106933727.000002902BA91000.00000004.00000800.00020000.00000000.sdmp, qqnal04.exe, 00000000.00000002.2106933727.000002902BBC5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: qqnal04.exe | String found in binary or memory: http://secure.globalsign.com/cacert/gsextendcodesignsha2g3ocsp.crt0 |
Source: qqnal04.exe | String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0 |
Source: qqnal04.exe, 00000000.00000002.2106933727.000002902BB20000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org |
Source: qqnal04.exe | String found in binary or memory: https://api.telegram.org/bot |
Source: qqnal04.exe, 00000000.00000002.2106933727.000002902BB20000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot7105371916:AAHmKYUFBY4gzPciIZ6nC4H-7mczREtwqxk/sendDocument |
Source: qqnal04.exe, 00000000.00000002.2106933727.000002902BA91000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot7105371916:AAHmKYUFBY4gzPciIZ6nC4H-7mczREtwqxk/sendDocument0 |
Source: qqnal04.exe, 00000000.00000002.2106933727.000002902BC76000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://get.geHj |
Source: qqnal04.exe, 00000000.00000002.2106933727.000002902BA91000.00000004.00000800.00020000.00000000.sdmp, qqnal04.exe, 00000000.00000002.2106933727.000002902BBC5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://get.geojs.io |
Source: qqnal04.exe, 00000000.00000002.2106933727.000002902BA91000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://get.geojs.io/v1/ip/geo.json |
Source: qqnal04.exe | String found in binary or memory: https://get.geojs.io/v1/ip/geo.json)root |
Source: qqnal04.exe | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: qqnal04.exe | String found in binary or memory: https://www.globalsign.com/repository/06 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2152 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 1720 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 3596 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 4732 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 420 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2140 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 5708 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 5152 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2132 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 1700 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2992 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 3852 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 5144 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 6000 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 1688 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 3840 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 3408 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 1252 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2104 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 6056 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 6496 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2528 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2096 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 3388 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 1232 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 368 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 5236 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 872 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 4672 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 3376 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 1220 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 788 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 3372 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 780 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2932 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 4652 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 1632 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 564 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2492 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 332 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2484 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 6792 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 1188 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 5496 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 5064 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 752 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 1612 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2472 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 3764 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 3304 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 1172 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2464 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 3756 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2836 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2456 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2024 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 5040 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 5636 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 5896 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 1584 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 6604 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 1660 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 1148 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2440 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 2868 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 280 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 5020 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 3724 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 5016 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 732 |
Source: C:\Users\user\Desktop\qqnal04.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT CommandLine FROM Win32_Process WHERE ProcessId = 4172 |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599891 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599781 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599672 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599562 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599453 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599344 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599219 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 598886 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 598671 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 598556 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 598402 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 598262 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 598140 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 598006 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -8301034833169293s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -599891s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -599781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -599672s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -599562s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -599453s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -599344s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -599219s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -599109s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -599000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -598886s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -598781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -598671s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -598556s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -598402s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -598262s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -598140s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 6172 | Thread sleep time: -598006s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 5512 | Thread sleep time: -30000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe TID: 7164 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599891 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599781 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599672 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599562 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599453 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599344 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599219 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 598886 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 598671 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 598556 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 598402 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 598262 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 598140 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 598006 | Jump to behavior |
Source: C:\Users\user\Desktop\qqnal04.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |