Source: Yara match | File source: 10.2.fontexport.exe.4116418.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.414cf50.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f46418.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.2dbcc7e.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f45530.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.2d0cc7e.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5410000.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.4116418.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.2c7cc7e.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.5630000.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5490000.9.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3f2cf50.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3ef6418.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.3.Di5RbqBHf7.exe.dd4798.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5490000.9.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.4115530.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.3.fontexport.exe.10530c8.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5410000.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5410ee8.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f45530.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f7cf50.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.3090000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.3090000.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.5460000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.54e0000.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.3.fontexport.exe.f5be40.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f46418.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.2d0db66.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.2dbdb66.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.3090ee8.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.3.fontexport.exe.10530c8.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3ef6418.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.5630000.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.2d0cc7e.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.3090ee8.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.3.fontexport.exe.f5be40.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.2d0db66.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.5460ee8.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3ef5530.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.4115530.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.5460000.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.54e0000.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3f2cf50.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f7cf50.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.2dbcc7e.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.2dbdb66.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5410ee8.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.414cf50.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.2c7cc7e.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.2c7db66.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3ef5530.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.5460ee8.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.2c7db66.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0000000A.00000002.760784794.0000000004115000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.723000914.0000000005410000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000002.756165726.0000000003111000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.717758426.0000000002EF1000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000002.756010982.0000000003090000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.933463091.0000000003F45000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000003.668587609.0000000000DD4000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.933572791.0000000005460000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000002.761044345.0000000005630000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.931691350.0000000002F41000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.932262130.0000000003013000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.727660213.0000000000F5B000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.933755258.00000000054E0000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.716855418.0000000002C3C000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000003.729198184.0000000001053000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000002.755269158.0000000002D7C000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.719786206.0000000003EF5000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.723116148.0000000005490000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.931138547.0000000002CCC000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: Di5RbqBHf7.exe PID: 6848, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: fontexport.exe PID: 7128, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: fontexport.exe PID: 7160, type: MEMORYSTR |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Code function: 0_2_02D4DF78 | 0_2_02D4DF78 |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Code function: 0_2_02D40C30 | 0_2_02D40C30 |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Code function: 10_2_02EFDF78 | 10_2_02EFDF78 |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Code function: 10_2_02EF0FF1 | 10_2_02EF0FF1 |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Code function: 10_2_02EF0C30 | 10_2_02EF0C30 |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Code function: 10_2_02EF0C10 | 10_2_02EF0C10 |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Code function: 11_2_02A2DF78 | 11_2_02A2DF78 |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Code function: 11_2_02A20C30 | 11_2_02A20C30 |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Code function: 11_2_0552E738 | 11_2_0552E738 |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Code function: 11_2_0552F008 | 11_2_0552F008 |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Code function: 11_2_0552E3F0 | 11_2_0552E3F0 |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Code function: 11_2_06780818 | 11_2_06780818 |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Code function: 11_2_06784560 | 11_2_06784560 |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Code function: 11_2_06784550 | 11_2_06784550 |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Code function: 11_2_06782211 | 11_2_06782211 |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Section loaded: msvcr120_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Section loaded: bcrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Section loaded: cldapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: msvcr120_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: bcrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: msvcr120_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: bcrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: cryptnet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: unknown | Process created: C:\Users\user\Desktop\Di5RbqBHf7.exe 'C:\Users\user\Desktop\Di5RbqBHf7.exe' | |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /tn 'fontexport' /tr ''C:\Users\user\AppData\Local\Temp\fontexport.exe'' & exit | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Users\user\AppData\Local\Temp\tmpCD69.tmp.bat'' | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /f /sc onlogon /rl highest /tn 'fontexport' /tr ''C:\Users\user\AppData\Local\Temp\fontexport.exe'' | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 3 | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\fontexport.exe C:\Users\user\AppData\Local\Temp\fontexport.exe | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\fontexport.exe 'C:\Users\user\AppData\Local\Temp\fontexport.exe' | |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /tn 'fontexport' /tr ''C:\Users\user\AppData\Local\Temp\fontexport.exe'' & exit | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Users\user\AppData\Local\Temp\tmpCD69.tmp.bat'' | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /f /sc onlogon /rl highest /tn 'fontexport' /tr ''C:\Users\user\AppData\Local\Temp\fontexport.exe'' | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 3 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\fontexport.exe 'C:\Users\user\AppData\Local\Temp\fontexport.exe' | Jump to behavior |
Source: Yara match | File source: 10.2.fontexport.exe.4116418.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.414cf50.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f46418.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.2dbcc7e.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f45530.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.2d0cc7e.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5410000.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.4116418.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.2c7cc7e.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.5630000.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5490000.9.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3f2cf50.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3ef6418.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.3.Di5RbqBHf7.exe.dd4798.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5490000.9.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.4115530.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.3.fontexport.exe.10530c8.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5410000.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5410ee8.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f45530.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f7cf50.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.3090000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.3090000.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.5460000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.54e0000.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.3.fontexport.exe.f5be40.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f46418.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.2d0db66.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.2dbdb66.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.3090ee8.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.3.fontexport.exe.10530c8.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3ef6418.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.5630000.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.2d0cc7e.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.3090ee8.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.3.fontexport.exe.f5be40.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.2d0db66.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.5460ee8.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3ef5530.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.4115530.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.5460000.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.54e0000.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3f2cf50.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f7cf50.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.2dbcc7e.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.2dbdb66.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5410ee8.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.414cf50.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.2c7cc7e.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.2c7db66.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3ef5530.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.5460ee8.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.2c7db66.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0000000A.00000002.760784794.0000000004115000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.723000914.0000000005410000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000002.756165726.0000000003111000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.717758426.0000000002EF1000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000002.756010982.0000000003090000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.933463091.0000000003F45000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000003.668587609.0000000000DD4000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.933572791.0000000005460000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000002.761044345.0000000005630000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.931691350.0000000002F41000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.932262130.0000000003013000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.727660213.0000000000F5B000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.933755258.00000000054E0000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.716855418.0000000002C3C000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000003.729198184.0000000001053000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000002.755269158.0000000002D7C000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.719786206.0000000003EF5000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.723116148.0000000005490000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.931138547.0000000002CCC000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: Di5RbqBHf7.exe PID: 6848, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: fontexport.exe PID: 7128, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: fontexport.exe PID: 7160, type: MEMORYSTR |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Memory written: PID: 6848 base: 28F0005 value: E9 FB BF 7F 74 | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Memory written: PID: 6848 base: 770EC000 value: E9 0A 40 80 8B | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Memory written: PID: 6848 base: 2A00008 value: E9 AB E0 72 74 | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Memory written: PID: 6848 base: 7712E0B0 value: E9 60 1F 8D 8B | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Memory written: PID: 6848 base: 2A20005 value: E9 CB 5A BB 71 | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Memory written: PID: 6848 base: 745D5AD0 value: E9 3A A5 44 8E | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Memory written: PID: 6848 base: 2A30005 value: E9 5B B0 BC 71 | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Memory written: PID: 6848 base: 745FB060 value: E9 AA 4F 43 8E | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Memory written: PID: 6848 base: 2A40005 value: E9 DB F8 07 72 | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Memory written: PID: 6848 base: 74ABF8E0 value: E9 2A 07 F8 8D | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Memory written: PID: 6848 base: 2A50005 value: E9 FB 42 09 72 | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Memory written: PID: 6848 base: 74AE4300 value: E9 0A BD F6 8D | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Memory written: PID: 6848 base: 2A70005 value: E9 FB 99 6A 74 | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Memory written: PID: 6848 base: 77119A00 value: E9 0A 66 95 8B | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7128 base: 2A20005 value: E9 FB BF 6C 74 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7128 base: 770EC000 value: E9 0A 40 93 8B | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7128 base: 2B30008 value: E9 AB E0 5F 74 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7128 base: 7712E0B0 value: E9 60 1F A0 8B | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7128 base: 2B50005 value: E9 CB 5A A8 71 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7128 base: 745D5AD0 value: E9 3A A5 57 8E | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7128 base: 2B60005 value: E9 5B B0 A9 71 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7128 base: 745FB060 value: E9 AA 4F 56 8E | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7128 base: 2B70005 value: E9 DB F8 F4 71 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7128 base: 74ABF8E0 value: E9 2A 07 0B 8E | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7128 base: 2B90005 value: E9 FB 42 F5 71 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7128 base: 74AE4300 value: E9 0A BD 0A 8E | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7128 base: 2BB0005 value: E9 FB 99 56 74 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7128 base: 77119A00 value: E9 0A 66 A9 8B | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7160 base: F40005 value: E9 FB BF 1A 76 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7160 base: 770EC000 value: E9 0A 40 E5 89 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7160 base: F50008 value: E9 AB E0 1D 76 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7160 base: 7712E0B0 value: E9 60 1F E2 89 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7160 base: F70005 value: E9 CB 5A 66 73 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7160 base: 745D5AD0 value: E9 3A A5 99 8C | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7160 base: F80005 value: E9 5B B0 67 73 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7160 base: 745FB060 value: E9 AA 4F 98 8C | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7160 base: F90005 value: E9 DB F8 B2 73 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7160 base: 74ABF8E0 value: E9 2A 07 4D 8C | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7160 base: FA0005 value: E9 FB 42 B4 73 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7160 base: 74AE4300 value: E9 0A BD 4B 8C | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7160 base: FB0005 value: E9 FB 99 16 76 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Memory written: PID: 7160 base: 77119A00 value: E9 0A 66 E9 89 | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Di5RbqBHf7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\fontexport.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: Yara match | File source: 10.2.fontexport.exe.4116418.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.414cf50.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f46418.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.2dbcc7e.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f45530.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.2d0cc7e.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5410000.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.4116418.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.2c7cc7e.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.5630000.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5490000.9.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3f2cf50.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3ef6418.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.3.Di5RbqBHf7.exe.dd4798.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5490000.9.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.4115530.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.3.fontexport.exe.10530c8.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5410000.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5410ee8.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f45530.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f7cf50.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.3090000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.3090000.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.5460000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.54e0000.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.3.fontexport.exe.f5be40.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f46418.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.2d0db66.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.2dbdb66.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.3090ee8.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.3.fontexport.exe.10530c8.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3ef6418.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.5630000.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.2d0cc7e.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.3090ee8.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.3.fontexport.exe.f5be40.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.2d0db66.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.5460ee8.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3ef5530.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.4115530.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.5460000.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.54e0000.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3f2cf50.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f7cf50.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.2dbcc7e.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.2dbdb66.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5410ee8.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.414cf50.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.2c7cc7e.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.2c7db66.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3ef5530.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.5460ee8.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.2c7db66.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0000000A.00000002.760784794.0000000004115000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.723000914.0000000005410000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000002.756165726.0000000003111000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.717758426.0000000002EF1000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000002.756010982.0000000003090000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.933463091.0000000003F45000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000003.668587609.0000000000DD4000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.933572791.0000000005460000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000002.761044345.0000000005630000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.931691350.0000000002F41000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.932262130.0000000003013000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.727660213.0000000000F5B000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.933755258.00000000054E0000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.716855418.0000000002C3C000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000003.729198184.0000000001053000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000002.755269158.0000000002D7C000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.719786206.0000000003EF5000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.723116148.0000000005490000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.931138547.0000000002CCC000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: Di5RbqBHf7.exe PID: 6848, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: fontexport.exe PID: 7128, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: fontexport.exe PID: 7160, type: MEMORYSTR |
Source: Yara match | File source: 10.2.fontexport.exe.4116418.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.414cf50.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f46418.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.2dbcc7e.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f45530.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.2d0cc7e.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5410000.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.4116418.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.2c7cc7e.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.5630000.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5490000.9.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3f2cf50.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3ef6418.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.3.Di5RbqBHf7.exe.dd4798.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5490000.9.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.4115530.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.3.fontexport.exe.10530c8.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5410000.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5410ee8.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f45530.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f7cf50.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.3090000.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.3090000.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.5460000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.54e0000.8.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.3.fontexport.exe.f5be40.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f46418.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.2d0db66.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.2dbdb66.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.3090ee8.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.3.fontexport.exe.10530c8.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3ef6418.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.5630000.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.2d0cc7e.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.3090ee8.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.3.fontexport.exe.f5be40.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.2d0db66.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.5460ee8.7.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3ef5530.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.4115530.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.5460000.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.54e0000.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3f2cf50.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.3f7cf50.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.2dbcc7e.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.2dbdb66.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.5410ee8.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.2.fontexport.exe.414cf50.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.2c7cc7e.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.2c7db66.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.3ef5530.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 11.2.fontexport.exe.5460ee8.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.Di5RbqBHf7.exe.2c7db66.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0000000A.00000002.760784794.0000000004115000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.723000914.0000000005410000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000002.756165726.0000000003111000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.717758426.0000000002EF1000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000002.756010982.0000000003090000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.933463091.0000000003F45000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000003.668587609.0000000000DD4000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.933572791.0000000005460000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000002.761044345.0000000005630000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.931691350.0000000002F41000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.932262130.0000000003013000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.727660213.0000000000F5B000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.933755258.00000000054E0000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.716855418.0000000002C3C000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000003.729198184.0000000001053000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000002.755269158.0000000002D7C000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.719786206.0000000003EF5000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.723116148.0000000005490000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000B.00000002.931138547.0000000002CCC000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: Di5RbqBHf7.exe PID: 6848, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: fontexport.exe PID: 7128, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: fontexport.exe PID: 7160, type: MEMORYSTR |