Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Recovery\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\3D Objects\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Contacts\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Desktop\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Desktop\GRXZDKKVDB\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Desktop\LSBIHQFDVT\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Desktop\PALRGUCVEH\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Desktop\PIVFAGEAAV\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Desktop\SUAVTZKNFL\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Desktop\ZQIXMVQGAH\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Documents\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Documents\GRXZDKKVDB\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Documents\LSBIHQFDVT\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Documents\PALRGUCVEH\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Documents\PIVFAGEAAV\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Documents\SUAVTZKNFL\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Documents\ZQIXMVQGAH\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Downloads\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Favorites\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Favorites\Links\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Links\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Music\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\OneDrive\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Pictures\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Pictures\Camera Roll\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Recent\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Saved Games\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Searches\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
File created: C:\Users\user\Videos\README.2c9ccbf3.TXT |
Jump to behavior |
Source: C:\Users\user\Desktop\fbi.exe |
Code function: 0_2_00404052 wcscpy,wcscat,FindFirstFileExW,wcscpy,wcscat,FindNextFileW,FindClose, |
0_2_00404052 |
Source: C:\Users\user\Desktop\fbi.exe |
Code function: 0_2_00403F75 wcscat,FindFirstFileExW,wcsrchr,wcscpy,FindNextFileW,FindClose, |
0_2_00403F75 |
Source: C:\Users\user\Desktop\fbi.exe |
Code function: 0_2_00404137 wcslen,RtlAllocateHeap,wcscpy,wcscat,FindFirstFileExW,wcslen,wcslen,RtlAllocateHeap,wcscpy,wcsrchr,wcscpy,GetFileAttributesW,RemoveDirectoryW,RtlFreeHeap,DeleteFileW,RtlFreeHeap,FindNextFileW,FindClose,RtlFreeHeap,RtlFreeHeap, |
0_2_00404137 |
Source: C:\Users\user\Desktop\fbi.exe |
Code function: 0_2_0040669A wcslen,RtlAllocateHeap,wcscpy,GetFileAttributesW,wcscat,FindFirstFileExW,wcslen,wcslen,RtlAllocateHeap,wcscpy,wcsrchr,wcscat,GetFileAttributesW,wcsstr,FindNextFileW,FindClose,RtlFreeHeap,RtlFreeHeap, |
0_2_0040669A |
Source: C:\Users\user\Desktop\fbi.exe |
Code function: 0_2_00401BA0 wcslen,RtlAllocateHeap,wcscpy,wcscat,FindFirstFileExW,FindNextFileW,FindClose,RtlFreeHeap, |
0_2_00401BA0 |
Source: svchost.exe, 00000019.00000003.328779807.0000023A50D3D000.00000004.00000001.sdmp |
String found in binary or memory: Try it free for 30 days, no strings attached\r\n\r\nLike us on Facebook: http://www.facebook.com/spotify \r\nFollow us on Twitter: http://twitter.com/spotify","ProductTitle":"Spotify Music","SearchTitles":[{"SearchTitleString":"Spotify","SearchTitleType":"SearchHint"},{"SearchTitleString":"Music","SearchTitleType":"SearchHint"},{"SearchTitleString":"music apps","SearchTitleType":"SearchHint"},{"SearchTitleString":"free music","SearchTitleType":"SearchHint"},{"SearchTitleString":"pandora","SearchTitleType":"SearchHint"},{"SearchTitleString":"streaming","SearchTitleType":"SearchHint"},{"SearchTitleString":"soundcloud","SearchTitleType":"SearchHint"}],"Language":"en-us","Markets":["US","DZ","AR","AU","AT","BH","BD","BE","BR","BG","CA","CL","CN","CO","CR","HR","CY","CZ","DK","EG","EE","FI","FR","DE","GR","GT","HK","HU","IS","IN","ID","IQ","IE","IL","IT","JP","JO","KZ","KE","KW","LV","LB","LI","LT","LU","MY","MT","MR","MX","MA","NL","NZ","NG","NO","OM","PK","PE","PH","PL","PT","QA","RO","RU","SA","RS","SG","SK","SI","ZA","KR","ES","SE","CH","TW","TH","TT","TN","TR","UA","AE","GB","VN","YE","LY","LK","UY","VE","AF","AX","AL","AS","AO","AI", equals www.facebook.com (Facebook) |
Source: svchost.exe, 00000019.00000003.328779807.0000023A50D3D000.00000004.00000001.sdmp |
String found in binary or memory: Try it free for 30 days, no strings attached\r\n\r\nLike us on Facebook: http://www.facebook.com/spotify \r\nFollow us on Twitter: http://twitter.com/spotify","ProductTitle":"Spotify Music","SearchTitles":[{"SearchTitleString":"Spotify","SearchTitleType":"SearchHint"},{"SearchTitleString":"Music","SearchTitleType":"SearchHint"},{"SearchTitleString":"music apps","SearchTitleType":"SearchHint"},{"SearchTitleString":"free music","SearchTitleType":"SearchHint"},{"SearchTitleString":"pandora","SearchTitleType":"SearchHint"},{"SearchTitleString":"streaming","SearchTitleType":"SearchHint"},{"SearchTitleString":"soundcloud","SearchTitleType":"SearchHint"}],"Language":"en-us","Markets":["US","DZ","AR","AU","AT","BH","BD","BE","BR","BG","CA","CL","CN","CO","CR","HR","CY","CZ","DK","EG","EE","FI","FR","DE","GR","GT","HK","HU","IS","IN","ID","IQ","IE","IL","IT","JP","JO","KZ","KE","KW","LV","LB","LI","LT","LU","MY","MT","MR","MX","MA","NL","NZ","NG","NO","OM","PK","PE","PH","PL","PT","QA","RO","RU","SA","RS","SG","SK","SI","ZA","KR","ES","SE","CH","TW","TH","TT","TN","TR","UA","AE","GB","VN","YE","LY","LK","UY","VE","AF","AX","AL","AS","AO","AI", equals www.twitter.com (Twitter) |
Source: svchost.exe, 00000019.00000003.328709410.0000023A50D59000.00000004.00000001.sdmp |
String found in binary or memory: Try it free for 30 days, no strings attached\r\n\r\nLike us on Facebook: http://www.facebook.com/spotify \r\nFollow us on Twitter: http://twitter.com/spotify","ProductTitle":"Spotify Music","SearchTitles":[{"SearchTitleString":"Spotify","SearchTitleType":"SearchHint"},{"SearchTitleString":"Music","SearchTitleType":"SearchHint"},{"SearchTitleString":"music apps","SearchTitleType":"SearchHint"},{"SearchTitleString":"free music","SearchTitleType":"SearchHint"},{"SearchTitleString":"pandora","SearchTitleType":"SearchHint"},{"SearchTitleString":"streaming","SearchTitleType":"SearchHint"},{"SearchTitleString":"soundcloud","SearchTitleType":"SearchHint"}],"Language":"en-us","Markets":["US","DZ","AR","AU","AT","BH","BD","BE","BR","BG","CA","CL","CN","CO","CR","HR","CY","CZ","DK","EG","EE","FI","FR","DE","GR","GT","HK","HU","IS","IN","ID","IQ","IE","IL","IT","JP","JO","KZ","KE","KW","LV","LB","LI","LT","LU","MY","MT","MR","MX","MA","NL","NZ","NG","NO","OM","PK","PE","PH","PL","PT","QA","RO","RU","SA","RS","SG","SK","SI","ZA","KR","ES","SE","CH","TW","TH","TT","TN","TR","UA","AE","GB","VN","YE","LY","LK","UY","VE","AF","AX","AL","AS","AO","AI","AQ","AG","AM","AW","BO","BQ","BA","BW","BV","IO","BN","BF","BI","KH","CM","CV","KY","CF","TD","TL","DJ","DM","DO","EC","SV","GQ","ER","ET","FK","FO","FJ","GF","PF","TF","GA","GM","GE","GH","GI","GL","GD","GP","GU","GG","GN","GW","GY","HT","HM","HN","AZ","BS","BB","BY","BZ","BJ","BM","BT","KM","CG","CD","CK","CX","CC","CI","CW","JM","SJ","JE","KI","KG","LA","LS","LR","MO","MK","MG","MW","IM","MH","MQ","MU","YT","FM","MD","MN","MS","MZ","MM","NA","NR","NP","MV","ML","NC","NI","NE","NU","NF","PW","PS","PA","PG","PY","RE","RW","BL","MF","WS","ST","SN","MP","PN","SX","SB","SO","SC","SL","GS","SH","KN","LC","PM","VC","TJ","TZ","TG","TK","TO","TM","TC","TV","UM","UG","VI","VG","WF","EH","ZM","ZW","UZ","VU","SR","SZ","AD","MC","SM","ME","VA","NEUTRAL"]}],"MarketProperties":[{"RelatedProducts":[],"Markets":["US"]}],"ProductASchema":"Product;3","ProductBSchema":"ProductUnifiedApp;3","ProductId":"9NCBCSZSJRSB","Properties":{"PackageFamilyName":"SpotifyAB.SpotifyMusic_zpdnekdrzrea0","PackageIdentityName":"SpotifyAB.SpotifyMusic","PublisherCertificateName":"CN=453637B3-4E12-4CDF-B0D3-2A3C863BF6EF","XboxCrossGenSetId":null,"XboxConsoleGenOptimized":null,"XboxConsoleGenCompatible":null},"AlternateIds":[{"IdType":"LegacyWindowsStoreProductId","Value":"ceac5d3f-8a4f-40e1-9a67-76d9108c7cb5"},{"IdType":" |