Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/1085 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/1452 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/1452expand_integer_pow_expressionsThe |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/1512 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/1637 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/1936 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/2046 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/2152 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/2152skip_vs_constant_register_zeroIn |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/2162 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/2273 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/2517 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/2727 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/2894 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/2970 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/2978 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3027 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3045 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3078 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3153 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3205 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3206 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3243 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3246 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3246allow_clear_for_robust_resource_initSome |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3452 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3498 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3502 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3577 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3584 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3623 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3624 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3625 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3682 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3682allowES3OnFL10_0Allow |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3729 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3965 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3970 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/3997 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/4214 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/4267 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/4324 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/4339 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/4384 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/4405 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/4428 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/4551 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/4633 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/4646 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/4722 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/4722forceRobustResourceInitForce-enable |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/482 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/4836 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/4889 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/4901 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/4937 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5007 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5007disable_anisotropic_filteringDisable |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5055 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5061 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5281 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5371 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5375 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5421 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5430 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5469 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5535 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5577 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5658 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5658GPU.ANGLE.DisplayInitializeMSFrontend |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5750 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5750enableCompressingPipelineCacheInThreadPoolEnable |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/5901 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/6041 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/6041forceInitShaderVariablesForce-enable |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/6048 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/6141 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/6248 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/6439 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/6651 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/6692 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/6755 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/6878 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://anglebug.com/6929 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/1094869 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/110263 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/1144207 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/1165751 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/1165751Disable |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/1171371 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/1181068 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/1181193 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/308366 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/403957 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/565179 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/642227 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/642605 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/644669 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/650547 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/672380 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/709351 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/797243 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/809422 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/830046 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/849576 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/883276 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/927470 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/941620 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://crbug.com/941620allow_translate_uniform_block_to_structured_bufferThere |
Source: explorer.exe, 0000000F.00000000.85000649541.000000000DA99000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000000.85016232529.00000000109A9000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89206288165.000000000DAEC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/Omniroot2025.crl0 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://issuetracker.google.com/173636783 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: http://issuetracker.google.com/200067929 |
Source: screenCapture_1.3.2.exe, 00000012.00000003.85126462163.0000000001077000.00000004.00000020.00020000.00000000.sdmp, screenCapture_1.3.2.exe, 00000012.00000002.85132929362.0000000001078000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ns.a.0/sTy |
Source: screenCapture_1.3.2.exe, 00000012.00000003.85126462163.0000000001077000.00000004.00000020.00020000.00000000.sdmp, screenCapture_1.3.2.exe, 00000012.00000002.85132929362.0000000001078000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ns.adobe.c.0/ti |
Source: screenCapture_1.3.2.exe, 00000012.00000003.85126462163.0000000001077000.00000004.00000020.00020000.00000000.sdmp, screenCapture_1.3.2.exe, 00000012.00000002.85132929362.0000000001078000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ns.adobe.hotosh |
Source: screenCapture_1.3.2.exe, 00000012.00000003.85126462163.0000000001077000.00000004.00000020.00020000.00000000.sdmp, screenCapture_1.3.2.exe, 00000012.00000002.85132929362.0000000001078000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ns.adoraw-se |
Source: screenCapture_1.3.2.exe, 00000012.00000003.85126462163.0000000001077000.00000004.00000020.00020000.00000000.sdmp, screenCapture_1.3.2.exe, 00000012.00000002.85132929362.0000000001078000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ns.photo/ |
Source: GalacticFever.exe | String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: explorer.exe, 0000000F.00000000.84998865324.000000000D9F0000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89204191249.000000000D9F0000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys% |
Source: explorer.exe, 0000000F.00000000.85000649541.000000000DA99000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000000.85016232529.00000000109A9000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89206288165.000000000DAEC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0: |
Source: explorer.exe, 0000000F.00000002.89216649423.00000000109AE000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000000.85016232529.00000000109A9000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/Omniroot2025.crlsJ |
Source: explorer.exe, 0000000F.00000002.89216474419.00000000109A9000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000000.85000649541.000000000DA99000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000000.85016232529.00000000109A9000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.msocsp.com0 |
Source: explorer.exe, 0000000F.00000000.84966770680.0000000009E80000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000F.00000000.84925733778.0000000003380000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000F.00000002.89183924711.000000000AE80000.00000002.00000001.00040000.00000000.sdmp | String found in binary or memory: http://schemas.micro |
Source: explorer.exe, 0000000F.00000002.89191617477.000000000D462000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000000.84981202666.000000000D446000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://schemas.microsoft.c |
Source: explorer.exe, 0000000F.00000000.84947899900.0000000009790000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89167319487.0000000009796000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://www.foreca.com |
Source: explorer.exe, 0000000F.00000002.89205592740.000000000DAAF000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://activity.windows.com/UserActivity.ReadWrite.CreatedByAppexeP |
Source: explorer.exe, 0000000F.00000002.89205592740.000000000DAAF000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://activity.windows.com/UserActivity.ReadWrite.CreatedByAppgHe |
Source: explorer.exe, 0000000F.00000000.84952853422.00000000098A4000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89171444518.00000000098A4000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/odirm32.dll |
Source: explorer.exe, 0000000F.00000002.89211998321.0000000010761000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://android.notify.windows.com/iOS |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://anglebug.com/4674 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://anglebug.com/4849 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://anglebug.com/5140 |
Source: explorer.exe, 0000000F.00000002.89213023123.00000000108F3000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000000.85012702447.00000000108F3000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com/ |
Source: explorer.exe, 0000000F.00000002.89213023123.00000000108F3000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000000.85012702447.00000000108F3000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com/m |
Source: explorer.exe, 0000000F.00000000.85012702447.00000000108F3000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000000.84915177879.0000000000DC9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com/v1/News/Feed/Windows?apikey=qrUeHGGYvVowZJuHA3XaH0uUvg1ZJ0GUZnXk3mxxPF&ocid=wind |
Source: explorer.exe, 0000000F.00000000.84925815846.0000000003390000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89153126882.0000000003390000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com/v1/news/Feed/Windows? |
Source: explorer.exe, 0000000F.00000000.84947899900.0000000009790000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89167319487.0000000009796000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com/v1/news/Feed/Windows?activityId=5696A836803C42E0B53F7BB2770E5342&timeOut=10000&o |
Source: explorer.exe, 0000000F.00000000.84947899900.0000000009790000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000000.84925815846.0000000003390000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89167319487.0000000009796000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89153126882.0000000003390000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com:443/v1/news/Feed/Windows? |
Source: explorer.exe, 0000000F.00000002.89175835745.00000000099CC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000000.84958002290.00000000099CC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.comj |
Source: explorer.exe, 0000000F.00000000.84947899900.0000000009790000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89167319487.0000000009796000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://assets.msn.com/weathermapdata/1/static/svg/72/MostlySunnyDay.svg |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://chromium.googlesource.com/angle/angle/ |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://crbug.com/1042393 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://crbug.com/1046462 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://crbug.com/1060012 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://crbug.com/1091824 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://crbug.com/1137851 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://crbug.com/593024 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://crbug.com/593024select_view_in_geometry_shaderThe |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://crbug.com/650547 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://crbug.com/650547call_clear_twiceUsing |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://crbug.com/655534 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://crbug.com/655534use_system_memory_for_constant_buffersCopying |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://crbug.com/705865 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://crbug.com/710443 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://crbug.com/811661 |
Source: explorer.exe, 0000000F.00000000.85015836556.0000000010996000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000000.85012702447.00000000108F3000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://deff.nelreports.net/api/report?cat=msn |
Source: explorer.exe, 0000000F.00000000.85000649541.000000000DA99000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89206288165.000000000DAEC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://excel.office.coma |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://issuetracker.google.com/161903006 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://issuetracker.google.com/166809097 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://issuetracker.google.com/184850002 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://issuetracker.google.com/187425444 |
Source: libGLESv2.dll2.1.dr | String found in binary or memory: https://issuetracker.google.com/issues/166475273 |
Source: explorer.exe, 0000000F.00000000.85000649541.000000000DA99000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89206288165.000000000DAEC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89188863283.000000000D3A0000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000000.84978229230.000000000D3A0000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://outlook.com |
Source: explorer.exe, 0000000F.00000002.89191617477.000000000D462000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000000.84981202666.000000000D446000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://powerpoint.office.come; |
Source: ja.pak.1.dr, th.pak.1.dr, hr.pak0.1.dr, nl.pak0.1.dr | String found in binary or memory: https://support.google.com/chrome/answer/6098869 |
Source: explorer.exe, 0000000F.00000000.84928448687.000000000342A000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://windows.msn.cn/shellRESP |
Source: explorer.exe, 0000000F.00000000.84947899900.0000000009790000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89167319487.0000000009796000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://windows.msn.com:443/shell |
Source: explorer.exe, 0000000F.00000002.89211998321.0000000010761000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://wns.windows.com/h |
Source: explorer.exe, 0000000F.00000000.85000649541.000000000DA99000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89206288165.000000000DAEC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89188863283.000000000D3A0000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000000.84978229230.000000000D3A0000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://word.office.com |
Source: explorer.exe, 0000000F.00000000.84925815846.0000000003390000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89153126882.0000000003390000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000000.84929999186.0000000003484000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.digicert.com/CPS0 |
Source: explorer.exe, 0000000F.00000000.84947899900.0000000009790000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89167319487.0000000009796000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/news/crime/charges-man-snapped-killed-4-then-left-bodies-in-field/ar-AAOGa |
Source: explorer.exe, 0000000F.00000000.84947899900.0000000009790000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89167319487.0000000009796000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/news/technology/facebook-oversight-board-reviewing-xcheck-system-for-vips/ |
Source: explorer.exe, 0000000F.00000000.84947899900.0000000009790000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89167319487.0000000009796000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/news/technology/stunning-image-shows-moon-crater-caused-by-asteroid-impact |
Source: explorer.exe, 0000000F.00000000.84947899900.0000000009790000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89167319487.0000000009796000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/news/us/texas-gov-abbott-sends-miles-of-cars-along-border-to-deter-migrant |
Source: explorer.exe, 0000000F.00000000.84947899900.0000000009790000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89167319487.0000000009796000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/tv/celebrity/tarek-el-moussa-tests-positive-for-covid-19-shuts-down-filmin |
Source: explorer.exe, 0000000F.00000000.84947899900.0000000009790000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.89167319487.0000000009796000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com:443/en-us/feed |
Source: unknown | Process created: C:\Users\user\Desktop\GalacticFever.exe "C:\Users\user\Desktop\GalacticFever.exe" | |
Source: C:\Users\user\Desktop\GalacticFever.exe | Process created: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe "C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe" --type=gpu-process --user-data-dir="C:\Users\user\AppData\Roaming\GalacticFever" --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1736 --field-trial-handle=1884,i,767538444076131274,5591825107057143823,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c ""C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.bat" "C:\Users\user\AppData\Local\Temp\epsilon-user\screenshot.png" " | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe screenCapture_1.3.2.exe "C:\Users\user\AppData\Local\Temp\epsilon-user\screenshot.png" | |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Windows\System32\cscript.exe cscript.exe | |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Windows\System32\cscript.exe cscript.exe | |
Source: C:\Windows\System32\cscript.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cscript.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Windows\System32\cscript.exe cscript.exe //Nologo C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar\node_modules\regedit\vbs\regList.wsf A "HKCU\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions" | |
Source: C:\Windows\System32\cscript.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Windows\System32\cscript.exe cscript.exe //Nologo C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar\node_modules\regedit\vbs\regList.wsf A HKCU\SOFTWARE\Valve\Steam | |
Source: C:\Windows\System32\cscript.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe "C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\user\AppData\Roaming\GalacticFever" --mojo-platform-channel-handle=2036 --field-trial-handle=1884,i,767538444076131274,5591825107057143823,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe "C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe" --type=renderer --user-data-dir="C:\Users\user\AppData\Roaming\GalacticFever" --app-path="C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar" --enable-sandbox --lang=en-US --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=4 --launch-time-ticks=8531136591 --mojo-platform-channel-handle=2320 --field-trial-handle=1884,i,767538444076131274,5591825107057143823,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1 | |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe "C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=32902 --gpu-device-id=16024 --gpu-sub-system-id=1050155081 --gpu-revision=2 --gpu-driver-version=27.20.100.9415 --user-data-dir="C:\Users\user\AppData\Roaming\GalacticFever" --gpu-preferences=UAAAAAAAAADoAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=3576 --field-trial-handle=1884,i,767538444076131274,5591825107057143823,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | |
Source: C:\Users\user\Desktop\GalacticFever.exe | Process created: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe "C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe" --type=gpu-process --user-data-dir="C:\Users\user\AppData\Roaming\GalacticFever" --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1736 --field-trial-handle=1884,i,767538444076131274,5591825107057143823,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c ""C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.bat" "C:\Users\user\AppData\Local\Temp\epsilon-user\screenshot.png" " | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Windows\System32\cscript.exe cscript.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Windows\System32\cscript.exe cscript.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Windows\System32\cscript.exe cscript.exe //Nologo C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar\node_modules\regedit\vbs\regList.wsf A "HKCU\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Windows\System32\cscript.exe cscript.exe //Nologo C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar\node_modules\regedit\vbs\regList.wsf A HKCU\SOFTWARE\Valve\Steam | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe "C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\user\AppData\Roaming\GalacticFever" --mojo-platform-channel-handle=2036 --field-trial-handle=1884,i,767538444076131274,5591825107057143823,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe "C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe" --type=renderer --user-data-dir="C:\Users\user\AppData\Roaming\GalacticFever" --app-path="C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar" --enable-sandbox --lang=en-US --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=4 --launch-time-ticks=8531136591 --mojo-platform-channel-handle=2320 --field-trial-handle=1884,i,767538444076131274,5591825107057143823,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process created: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe "C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=32902 --gpu-device-id=16024 --gpu-sub-system-id=1050155081 --gpu-revision=2 --gpu-driver-version=27.20.100.9415 --user-data-dir="C:\Users\user\AppData\Roaming\GalacticFever" --gpu-preferences=UAAAAAAAAADoAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=3576 --field-trial-handle=1884,i,767538444076131274,5591825107057143823,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe screenCapture_1.3.2.exe "C:\Users\user\AppData\Local\Temp\epsilon-user\screenshot.png" | Jump to behavior |
Source: libEGL.dll.1.dr | Static PE information: section name: .00cfg |
Source: libEGL.dll.1.dr | Static PE information: section name: _RDATA |
Source: libGLESv2.dll.1.dr | Static PE information: section name: .00cfg |
Source: libGLESv2.dll.1.dr | Static PE information: section name: _RDATA |
Source: ffmpeg.dll.1.dr | Static PE information: section name: .00cfg |
Source: ffmpeg.dll.1.dr | Static PE information: section name: _RDATA |
Source: GalacticFever.exe.1.dr | Static PE information: section name: .00cfg |
Source: GalacticFever.exe.1.dr | Static PE information: section name: .retplne |
Source: GalacticFever.exe.1.dr | Static PE information: section name: .rodata |
Source: GalacticFever.exe.1.dr | Static PE information: section name: CPADinfo |
Source: GalacticFever.exe.1.dr | Static PE information: section name: _RDATA |
Source: GalacticFever.exe.1.dr | Static PE information: section name: malloc_h |
Source: libEGL.dll0.1.dr | Static PE information: section name: .00cfg |
Source: libEGL.dll0.1.dr | Static PE information: section name: _RDATA |
Source: libGLESv2.dll0.1.dr | Static PE information: section name: .00cfg |
Source: libGLESv2.dll0.1.dr | Static PE information: section name: _RDATA |
Source: libEGL.dll1.1.dr | Static PE information: section name: .00cfg |
Source: libEGL.dll1.1.dr | Static PE information: section name: _RDATA |
Source: libGLESv2.dll1.1.dr | Static PE information: section name: .00cfg |
Source: libGLESv2.dll1.1.dr | Static PE information: section name: _RDATA |
Source: vk_swiftshader.dll.1.dr | Static PE information: section name: .00cfg |
Source: vk_swiftshader.dll.1.dr | Static PE information: section name: _RDATA |
Source: vulkan-1.dll.1.dr | Static PE information: section name: .00cfg |
Source: vulkan-1.dll.1.dr | Static PE information: section name: _RDATA |
Source: ffmpeg.dll0.1.dr | Static PE information: section name: .00cfg |
Source: ffmpeg.dll0.1.dr | Static PE information: section name: _RDATA |
Source: GalacticFever.exe0.1.dr | Static PE information: section name: .00cfg |
Source: GalacticFever.exe0.1.dr | Static PE information: section name: .retplne |
Source: GalacticFever.exe0.1.dr | Static PE information: section name: .rodata |
Source: GalacticFever.exe0.1.dr | Static PE information: section name: CPADinfo |
Source: GalacticFever.exe0.1.dr | Static PE information: section name: _RDATA |
Source: GalacticFever.exe0.1.dr | Static PE information: section name: malloc_h |
Source: libEGL.dll2.1.dr | Static PE information: section name: .00cfg |
Source: libEGL.dll2.1.dr | Static PE information: section name: _RDATA |
Source: libGLESv2.dll2.1.dr | Static PE information: section name: .00cfg |
Source: libGLESv2.dll2.1.dr | Static PE information: section name: _RDATA |
Source: vk_swiftshader.dll0.1.dr | Static PE information: section name: .00cfg |
Source: vk_swiftshader.dll0.1.dr | Static PE information: section name: _RDATA |
Source: vulkan-1.dll0.1.dr | Static PE information: section name: .00cfg |
Source: vulkan-1.dll0.1.dr | Static PE information: section name: _RDATA |
Source: 70141593-64e7-4416-9423-9417705bd356.tmp.node.12.dr | Static PE information: section name: _RDATA |
Source: 337648c0-e5e8-4a07-8dbc-cc53519a8930.tmp.node.12.dr | Static PE information: section name: .didat |
Source: 337648c0-e5e8-4a07-8dbc-cc53519a8930.tmp.node.12.dr | Static PE information: section name: .00cfg |
Source: 337648c0-e5e8-4a07-8dbc-cc53519a8930.tmp.node.12.dr | Static PE information: section name: _RDATA |
Source: C:\Users\user\Desktop\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\resources\app.asar.unpacked\node_modules\screenshot-desktop\lib\win32\screenCapture_1.3.2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2Ci45pzFGytv5nzm98wKCl0qmls\GalacticFever.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |