Create Interactive Tour

Windows Analysis Report
SecuriteInfo.com.W32.AIDetectNet.01.24075.5367

Overview

General Information

Sample Name:SecuriteInfo.com.W32.AIDetectNet.01.24075.5367 (renamed file extension from 5367 to exe)
Analysis ID:680727
MD5:c021921cd23808cb0e4040d1fccd30d6
SHA1:3abb4eb5b6eae3c088c13698dd54eb06a2b8de48
SHA256:fac0d50307e72ddb6bddb0865c4053d9a9bb691641a12989594f71f0e6137d1f
Tags:exe
Infos:

Detection

FormBook
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Yara detected FormBook
Malicious sample detected (through community Yara rule)
Yara detected AntiVM3
Antivirus detection for URL or domain
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Machine Learning detection for sample
.NET source code contains potential unpacker
Injects a PE file into a foreign processes
Tries to detect virtualization through RDTSC time measurements
Machine Learning detection for dropped file
C2 URLs / IPs found in malware configuration
Adds a directory exclusion to Windows Defender
Uses schtasks.exe or at.exe to add and modify task schedules
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Yara signature match
Antivirus or Machine Learning detection for unpacked file
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Found potential string decryption / allocating functions
Sample execution stops while process was sleeping (likely an evasion)
Contains functionality to call native functions
Contains functionality for execution timing, often used to detect debuggers
Contains long sleeps (>= 3 min)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Sample file is different than original file name gathered from version info
Drops PE files
Contains functionality to read the PEB
Checks if the current process is being debugged
Found large amount of non-executed APIs
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • SecuriteInfo.com.W32.AIDetectNet.01.24075.exe (PID: 5436 cmdline: "C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe" MD5: C021921CD23808CB0E4040D1FCCD30D6)
    • powershell.exe (PID: 1892 cmdline: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\inhPIwYnDIR.exe MD5: DBA3E6449E97D4E3DF64527EF7012A10)
      • conhost.exe (PID: 1564 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • schtasks.exe (PID: 6108 cmdline: C:\Windows\System32\schtasks.exe" /Create /TN "Updates\inhPIwYnDIR" /XML "C:\Users\user\AppData\Local\Temp\tmpF1DA.tmp MD5: 15FF7D8324231381BAD48A052F85DF04)
      • conhost.exe (PID: 5080 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • cleanup
{
  "C2 list": [
    "www.josephfoodbank.com/ck12/"
  ],
  "decoy": [
    "shallowdevs.com",
    "housecleaning-be.life",
    "care-con.com",
    "mazarineinc.com",
    "esmegillman.com",
    "remastersro.com",
    "tianfenfen.xyz",
    "inossemglobal.com",
    "wwwsaferent.com",
    "tiny-claws.com",
    "theoneshotmedia.com",
    "halatitriyom.website",
    "wingtools.xyz",
    "thesymphonyplan.com",
    "ikeda-nash.com",
    "betexpergo.com",
    "fooklin.com",
    "9isfuy.com",
    "nvcxsaea.info",
    "flockofwolves.com",
    "cannapandas.biz",
    "twugger.site",
    "praisethesatan.com",
    "jiropeu.life",
    "cargoforce-delivery.com",
    "restlesswildflowerstave.website",
    "camillegirard.com",
    "dftraduccion.com",
    "junhodigital.xyz",
    "nearexamplechord.xyz",
    "toshopshopshop.com",
    "uniradio.online",
    "malahame.com",
    "czshags.com",
    "spacex365.space",
    "maenolar.com",
    "standardbullets.com",
    "trumlor.online",
    "dadafenqi.com",
    "231088.top",
    "martualterada.com",
    "eliteatl.xyz",
    "118smitchell.info",
    "nauticomp.site",
    "cogroos.com",
    "acty.site",
    "0579n.beauty",
    "gokcealankoyu.com",
    "arthurliveson.com",
    "takablog0911.website",
    "twogeinu.com",
    "spiketool.site",
    "chatdevelopers.com",
    "boxermoulinprogot.com",
    "aboutpdf.net",
    "atlantaartclasses.com",
    "yr2038.com",
    "vision-hhc.com",
    "milestonemonth.store",
    "strategyfactory.xyz",
    "dandsfabrication.com",
    "dutchseeds.xyz",
    "alertaseguros.net",
    "ecoqrcode.com"
  ]
}
SourceRuleDescriptionAuthorStrings
00000000.00000002.265953049.0000000002F62000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_AntiVM_3Yara detected AntiVM_3Joe Security
    00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_FormBookYara detected FormBookJoe Security
      00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmpWindows_Trojan_Formbook_1112e116unknownunknown
      • 0x5251:$a1: 3C 30 50 4F 53 54 74 09 40
      • 0x1bbc0:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
      • 0x99cf:$a3: 1A D2 80 E2 AF 80 C2 7E EB 2A 80 FA 2F 75 11 8A D0 80 E2 01
      • 0x148b7:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
      00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmpFormbook_1autogenerated rule brought to you by yara-signatorFelix Bilstein - yara-signator at cocacoding dot com
      • 0x8908:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
      • 0x8b82:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
      • 0x146b5:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
      • 0x141a1:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
      • 0x147b7:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
      • 0x1492f:$sequence_4: 5D C3 8D 50 7C 80 FA 07
      • 0x959a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
      • 0x1341c:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
      • 0xa293:$sequence_7: 66 89 0C 02 5B 8B E5 5D
      • 0x1a927:$sequence_8: 3C 54 74 04 3C 74 75 F4
      • 0x1b92a:$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
      00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmpFormbookdetect Formbook in memoryJPCERT/CC Incident Response Group
      • 0x17849:$sqlite3step: 68 34 1C 7B E1
      • 0x1795c:$sqlite3step: 68 34 1C 7B E1
      • 0x17878:$sqlite3text: 68 38 2A 90 C5
      • 0x1799d:$sqlite3text: 68 38 2A 90 C5
      • 0x1788b:$sqlite3blob: 68 53 D8 7F 8C
      • 0x179b3:$sqlite3blob: 68 53 D8 7F 8C
      Click to see the 8 entries
      SourceRuleDescriptionAuthorStrings
      9.0.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.400000.0.unpackJoeSecurity_FormBookYara detected FormBookJoe Security
        9.0.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.400000.0.unpackWindows_Trojan_Formbook_1112e116unknownunknown
        • 0x5451:$a1: 3C 30 50 4F 53 54 74 09 40
        • 0x1bdc0:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
        • 0x9bcf:$a3: 1A D2 80 E2 AF 80 C2 7E EB 2A 80 FA 2F 75 11 8A D0 80 E2 01
        • 0x14ab7:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
        9.0.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.400000.0.unpackFormbook_1autogenerated rule brought to you by yara-signatorFelix Bilstein - yara-signator at cocacoding dot com
        • 0x8b08:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
        • 0x8d82:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
        • 0x148b5:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
        • 0x143a1:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
        • 0x149b7:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
        • 0x14b2f:$sequence_4: 5D C3 8D 50 7C 80 FA 07
        • 0x979a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
        • 0x1361c:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
        • 0xa493:$sequence_7: 66 89 0C 02 5B 8B E5 5D
        • 0x1ab27:$sequence_8: 3C 54 74 04 3C 74 75 F4
        • 0x1bb2a:$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
        9.0.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.400000.0.unpackFormbookdetect Formbook in memoryJPCERT/CC Incident Response Group
        • 0x17a49:$sqlite3step: 68 34 1C 7B E1
        • 0x17b5c:$sqlite3step: 68 34 1C 7B E1
        • 0x17a78:$sqlite3text: 68 38 2A 90 C5
        • 0x17b9d:$sqlite3text: 68 38 2A 90 C5
        • 0x17a8b:$sqlite3blob: 68 53 D8 7F 8C
        • 0x17bb3:$sqlite3blob: 68 53 D8 7F 8C
        0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3d77138.5.raw.unpackJoeSecurity_FormBookYara detected FormBookJoe Security
          Click to see the 7 entries
          No Sigma rule has matched
          No Snort rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exeVirustotal: Detection: 24%Perma Link
          Source: Yara matchFile source: 9.0.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3d77138.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3cd9930.6.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000000.00000002.266377783.0000000003CD1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: www.josephfoodbank.com/ck12/Avira URL Cloud: Label: malware
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exeJoe Sandbox ML: detected
          Source: C:\Users\user\AppData\Roaming\inhPIwYnDIR.exeJoe Sandbox ML: detected
          Source: 9.0.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.400000.0.unpackAvira: Label: TR/Crypt.ZPACK.Gen
          Source: 00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmpMalware Configuration Extractor: FormBook {"C2 list": ["www.josephfoodbank.com/ck12/"], "decoy": ["shallowdevs.com", "housecleaning-be.life", "care-con.com", "mazarineinc.com", "esmegillman.com", "remastersro.com", "tianfenfen.xyz", "inossemglobal.com", "wwwsaferent.com", "tiny-claws.com", "theoneshotmedia.com", "halatitriyom.website", "wingtools.xyz", "thesymphonyplan.com", "ikeda-nash.com", "betexpergo.com", "fooklin.com", "9isfuy.com", "nvcxsaea.info", "flockofwolves.com", "cannapandas.biz", "twugger.site", "praisethesatan.com", "jiropeu.life", "cargoforce-delivery.com", "restlesswildflowerstave.website", "camillegirard.com", "dftraduccion.com", "junhodigital.xyz", "nearexamplechord.xyz", "toshopshopshop.com", "uniradio.online", "malahame.com", "czshags.com", "spacex365.space", "maenolar.com", "standardbullets.com", "trumlor.online", "dadafenqi.com", "231088.top", "martualterada.com", "eliteatl.xyz", "118smitchell.info", "nauticomp.site", "cogroos.com", "acty.site", "0579n.beauty", "gokcealankoyu.com", "arthurliveson.com", "takablog0911.website", "twogeinu.com", "spiketool.site", "chatdevelopers.com", "boxermoulinprogot.com", "aboutpdf.net", "atlantaartclasses.com", "yr2038.com", "vision-hhc.com", "milestonemonth.store", "strategyfactory.xyz", "dandsfabrication.com", "dutchseeds.xyz", "alertaseguros.net", "ecoqrcode.com"]}
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
          Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000009.00000003.263252416.00000000016A8000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000009.00000003.260006284.0000000001511000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000009.00000002.265153723.0000000001840000.00000040.00000800.00020000.00000000.sdmp
          Source: Binary string: wntdll.pdb source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000009.00000003.263252416.00000000016A8000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000009.00000003.260006284.0000000001511000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000009.00000002.265153723.0000000001840000.00000040.00000800.00020000.00000000.sdmp

          Networking

          barindex
          Source: Malware configuration extractorURLs: www.josephfoodbank.com/ck12/
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230679142.0000000005C20000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://en.wikip
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://fontfabrik.com
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.265953049.0000000002F62000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.264390802.0000000002D44000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231377753.0000000005C1D000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231198964.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231600471.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231239007.0000000005C20000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.com
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231041899.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231077425.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231062729.0000000005C19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.com.
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231249662.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231211075.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231189973.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231284013.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231231688.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231307976.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231266555.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.comR
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231538257.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231558138.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231609757.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231503175.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231513867.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231578595.0000000005C20000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.comTC
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231609757.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231578595.0000000005C20000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.comX
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231169117.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231219511.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231198964.0000000005C20000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.comcn
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231446583.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231476574.0000000005C1D000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231356394.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231426384.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231377753.0000000005C1D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.comead#
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231570209.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231325851.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231249662.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231211075.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231528192.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231446583.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231189973.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231343075.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231494427.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231284013.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231231688.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231307976.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231356394.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231426384.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231513867.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231266555.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231550741.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231132980.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.comk
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231169117.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231219511.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231256409.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231609757.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231273161.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231503175.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231455460.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231578595.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231114511.0000000005C1D000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231198964.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231239007.0000000005C20000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.coml
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231570209.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231325851.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231249662.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231211075.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231528192.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231446583.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231343075.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231494427.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231284013.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231231688.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231307976.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231356394.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231426384.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231513867.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231266555.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231550741.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.comm
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231256409.0000000005C20000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.comn-u
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231538257.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231482683.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231558138.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231609757.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231503175.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231513867.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231578595.0000000005C20000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.comncy
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231513867.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.comona
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231446583.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231476574.0000000005C1D000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231426384.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231377753.0000000005C1D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.comrr:
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231077425.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231683857.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231062729.0000000005C19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.comt-pA
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231538257.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231558138.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231609757.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231578595.0000000005C20000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.comtig
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231570209.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231528192.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231550741.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231600471.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.comx
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235460068.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234816097.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235203989.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236117754.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236392198.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235729648.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236347292.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234382164.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234698937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234964795.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235690463.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235272067.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236031937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235322022.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236493830.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235781420.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236246817.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236168084.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235535126.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234773422.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236117754.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235729648.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236031937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235781420.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235955510.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235997702.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235912222.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com.TTFT
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/?
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/frere-user.html
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers8
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers?
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersG
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234239765.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com9
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239586438.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269173777.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239497582.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239309017.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239397211.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comB.TTFy
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235203989.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236117754.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236392198.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235729648.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236347292.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235272067.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236031937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235322022.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236493830.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236246817.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236168084.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235401265.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235427394.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236211639.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236319656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236418829.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236368072.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235145530.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236570276.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235024440.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236458188.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comF
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236117754.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236392198.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235729648.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236347292.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235690463.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236031937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236493830.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235781420.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236246817.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236168084.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236211639.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236319656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236418829.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235955510.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236368072.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236570276.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235997702.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236458188.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235912222.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comFn
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234382164.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234270662.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234317595.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comK
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235203989.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235272067.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235322022.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235401265.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235427394.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235145530.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comR.TTF
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236392198.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236347292.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236246817.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236168084.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236211639.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236319656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236418829.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236368072.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236458188.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comT
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235203989.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235272067.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235322022.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235401265.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235427394.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235145530.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235024440.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comW.TTF5
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239277378.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239586438.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269173777.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239497582.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239309017.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239397211.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.coma
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234816097.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235203989.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234698937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234964795.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235272067.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235322022.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234773422.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235401265.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235427394.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235145530.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235024440.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234902484.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234850708.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comalic
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236117754.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236392198.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236347292.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236031937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236493830.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236246817.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236168084.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236211639.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236319656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236418829.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236368072.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236570276.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236458188.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comalsa
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236117754.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236392198.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235729648.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236347292.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235690463.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236031937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236493830.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235781420.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236246817.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236168084.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236211639.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236319656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236418829.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235955510.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236368072.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236570276.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235997702.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236458188.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235912222.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comcom
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234617673.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comd
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234816097.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235203989.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234698937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234617673.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234964795.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234773422.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235145530.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235024440.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234902484.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234850708.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.come.com
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239277378.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239586438.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269173777.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239497582.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239309017.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239397211.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comicomK
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235571385.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comitu
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239309017.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comn
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234239765.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comony
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234382164.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234270662.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234317595.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comtalik
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fonts.com
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230812104.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230645268.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230786348.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230612048.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230663964.0000000005C18000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230645268.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230786348.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230612048.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230663964.0000000005C18000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn%
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230497918.0000000005C1B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230521856.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230428147.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230366877.0000000005C18000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230812104.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230786348.0000000005C18000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/_
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/bThe
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/cThe
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230663964.0000000005C18000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cntoi
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.237292361.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/DPlease
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.261253820.0000000005BF0000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htmZTi
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.goodfont.co.kr
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232828269.0000000005C19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232544689.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232867696.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232640563.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232720289.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232344057.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232828269.0000000005C19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp//
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232544689.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232943240.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232969656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232180963.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232388258.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232471880.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232867696.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232417223.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232640563.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232720289.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232999954.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232913704.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232344057.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232141879.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232828269.0000000005C19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/8
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232388258.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/B
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232544689.0000000005C18000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/K
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232544689.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232180963.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232388258.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232867696.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232640563.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232720289.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232344057.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232141879.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232828269.0000000005C19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/T
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232544689.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232943240.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232969656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232471880.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232867696.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232417223.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232640563.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232720289.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232999954.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232913704.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232828269.0000000005C19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/a-d5
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232544689.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232943240.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232969656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232180963.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232388258.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232471880.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232867696.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232417223.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232640563.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232720289.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232089772.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232999954.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232913704.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232344057.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232141879.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232828269.0000000005C19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/jp/
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232388258.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232471880.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232417223.0000000005C18000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/jp//
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232544689.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232471880.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232417223.0000000005C18000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/jp/B
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232471880.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232417223.0000000005C18000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/jp/T
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232544689.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232867696.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232640563.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232720289.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232828269.0000000005C19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/jp/y
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232471880.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232417223.0000000005C18000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/y
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228876459.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228858447.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228729579.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228908013.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228706179.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228754890.0000000005C0B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.com
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228876459.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228858447.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228729579.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228908013.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228706179.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228754890.0000000005C0B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.com0
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228876459.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228858447.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228729579.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228908013.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228706179.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228754890.0000000005C0B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.coma
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228876459.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228858447.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228729579.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228908013.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228706179.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228754890.0000000005C0B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.come
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228876459.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228858447.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228729579.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228908013.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228706179.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228754890.0000000005C0B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.comtu
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232867696.0000000005C19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sakkal.com
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232867696.0000000005C19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sakkal.comX
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sandoll.co.kr
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231600471.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.tiro.com
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231600471.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.tiro.comB
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231683857.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231600471.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.tiro.comslnt
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.typography.netD
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236246817.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236319656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236418829.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236368072.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234131522.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.urwpp.de
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236246817.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236319656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.urwpp.de)
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234239765.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234103394.0000000005C1D000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234067778.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234203952.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234131522.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.urwpp.de5
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.urwpp.deDPlease
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234103394.0000000005C1D000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234067778.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234131522.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.urwpp.dea
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231041899.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231077425.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231018559.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231683857.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231062729.0000000005C19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.zhongyicts.com.cn
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231018559.0000000005C18000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.zhongyicts.com.cno.
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231041899.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231077425.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231018559.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231683857.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231062729.0000000005C19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.zhongyicts.com.cnt-b

          E-Banking Fraud

          barindex
          Source: Yara matchFile source: 9.0.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3d77138.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3cd9930.6.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000000.00000002.266377783.0000000003CD1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY

          System Summary

          barindex
          Source: 9.0.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
          Source: 9.0.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
          Source: 9.0.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
          Source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3d77138.5.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
          Source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3d77138.5.raw.unpack, type: UNPACKEDPEMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
          Source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3d77138.5.raw.unpack, type: UNPACKEDPEMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
          Source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3cd9930.6.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
          Source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3cd9930.6.raw.unpack, type: UNPACKEDPEMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
          Source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3cd9930.6.raw.unpack, type: UNPACKEDPEMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
          Source: 00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
          Source: 00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
          Source: 00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
          Source: 00000000.00000002.266377783.0000000003CD1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
          Source: 00000000.00000002.266377783.0000000003CD1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
          Source: 00000000.00000002.266377783.0000000003CD1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
          Source: Process Memory Space: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe PID: 5436, type: MEMORYSTRMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
          Source: Process Memory Space: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe PID: 1724, type: MEMORYSTRMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
          Source: 9.0.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
          Source: 9.0.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
          Source: 9.0.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
          Source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3d77138.5.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
          Source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3d77138.5.raw.unpack, type: UNPACKEDPEMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
          Source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3d77138.5.raw.unpack, type: UNPACKEDPEMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
          Source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3cd9930.6.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
          Source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3cd9930.6.raw.unpack, type: UNPACKEDPEMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
          Source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3cd9930.6.raw.unpack, type: UNPACKEDPEMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
          Source: 00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
          Source: 00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
          Source: 00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
          Source: 00000000.00000002.266377783.0000000003CD1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
          Source: 00000000.00000002.266377783.0000000003CD1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
          Source: 00000000.00000002.266377783.0000000003CD1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
          Source: Process Memory Space: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe PID: 5436, type: MEMORYSTRMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
          Source: Process Memory Space: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe PID: 1724, type: MEMORYSTRMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_02C6B754
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_02C6DC29
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_02C6DC38
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_07495F70
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_07495748
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_07495739
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_07497110
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_07497120
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_07495F10
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_07495F39
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187C1C0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01884120
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187B090
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018920A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019320A8
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019260F5
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01921002
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189701D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189138B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019203DA
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019123E3
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192231B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01883360
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019332A9
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019322AE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192E2C5
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B236
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01892581
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018965A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019325DD
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187D5E0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01924496
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187841F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01882430
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192D466
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B477
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019267E2
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018906C0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192D616
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01869660
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01882990
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018899BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186F900
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018688E0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019328EC
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01866800
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0193E824
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A830
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188EB9A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0190EB8A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189EBB0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192DBD2
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189ABD8
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018B8BE8
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01932B28
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188AB40
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0190CB4F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01924AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0191FA2B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01925A4F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01922D82
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01932D07
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01860D20
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01931D55
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01882D50
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01894CD4
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192CC77
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0193DFCE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01931FF1
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01911EB6
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01932EF7
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01886E30
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018EAE60
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: String function: 0186B150 appears 177 times
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: String function: 018BD08C appears 51 times
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: String function: 018F5720 appears 85 times
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A96E0 NtFreeVirtualMemory,LdrInitializeThunk,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9660 NtAllocateVirtualMemory,LdrInitializeThunk,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9860 NtQuerySystemInformation,LdrInitializeThunk,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018AB040 NtSuspendThread,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018AA3B0 NtGetContextThread,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A95D0 NtClose,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A95F0 NtQueryInformationFile,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9520 NtWaitForSingleObject,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9540 NtReadFile,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9560 NtWriteFile,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9780 NtMapViewOfSection,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A97A0 NtUnmapViewOfSection,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018AA710 NtOpenProcessToken,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9710 NtQueryInformationToken,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9730 NtQueryVirtualMemory,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9760 NtOpenProcess,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9770 NtSetInformationFile,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018AA770 NtOpenThread,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A96D0 NtCreateKey,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9610 NtEnumerateValueKey,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9650 NtQueryValueKey,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9670 NtQueryInformationProcess,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A99A0 NtCreateSection,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A99D0 NtCreateProcessEx,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9910 NtAdjustPrivilegesToken,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9950 NtQueueApcThread,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A98A0 NtWriteVirtualMemory,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A98F0 NtReadVirtualMemory,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9820 NtEnumerateKey,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9840 NtDelayExecution,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9B00 NtSetValueKey,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9A80 NtOpenDirectoryObject,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9A00 NtProtectVirtualMemory,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9A10 NtQuerySection,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9A20 NtResumeThread,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9A50 NtCreateFile,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018AAD30 NtSetContextThread,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A9FE0 NtCreateMutant,
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.264068406.0000000002CD1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameWebName.dll4 vs SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000000.224171354.000000000095C000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameSafeTypeNameParserHan.exe6 vs SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.270868040.00000000074A0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameDoncepre.dll@ vs SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.267398169.0000000003F07000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameDoncepre.dll@ vs SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.270636078.00000000072C0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameKeysNormalize.dll4 vs SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.243455033.0000000007671000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSafeTypeNameParserHan.exe6 vs SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.270808133.0000000007300000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameWebName.dll4 vs SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.266377783.0000000003CD1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameKeysNormalize.dll4 vs SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000009.00000003.261512373.0000000001627000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000009.00000002.265879857.000000000195F000.00000040.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000009.00000003.264140201.00000000017C7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exeBinary or memory string: OriginalFilenameSafeTypeNameParserHan.exe6 vs SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: inhPIwYnDIR.exe.0.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exeVirustotal: Detection: 24%
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeFile read: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeJump to behavior
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
          Source: unknownProcess created: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe "C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe"
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\inhPIwYnDIR.exe
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess created: C:\Windows\SysWOW64\schtasks.exe C:\Windows\System32\schtasks.exe" /Create /TN "Updates\inhPIwYnDIR" /XML "C:\Users\user\AppData\Local\Temp\tmpF1DA.tmp
          Source: C:\Windows\SysWOW64\schtasks.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\inhPIwYnDIR.exe
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess created: C:\Windows\SysWOW64\schtasks.exe C:\Windows\System32\schtasks.exe" /Create /TN "Updates\inhPIwYnDIR" /XML "C:\Users\user\AppData\Local\Temp\tmpF1DA.tmp
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeFile created: C:\Users\user\AppData\Roaming\inhPIwYnDIR.exeJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeFile created: C:\Users\user\AppData\Local\Temp\tmpF1DA.tmpJump to behavior
          Source: classification engineClassification label: mal100.troj.evad.winEXE@11/8@0/0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll
          Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5080:120:WilError_01
          Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1564:120:WilError_01
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, ATMManager/Main.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
          Source: inhPIwYnDIR.exe.0.dr, ATMManager/Main.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
          Source: Window RecorderWindow detected: More than 3 window changes detected
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exeStatic file information: File size 1095680 > 1048576
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
          Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000009.00000003.263252416.00000000016A8000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000009.00000003.260006284.0000000001511000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000009.00000002.265153723.0000000001840000.00000040.00000800.00020000.00000000.sdmp
          Source: Binary string: wntdll.pdb source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000009.00000003.263252416.00000000016A8000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000009.00000003.260006284.0000000001511000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000009.00000002.265153723.0000000001840000.00000040.00000800.00020000.00000000.sdmp

          Data Obfuscation

          barindex
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, ATMManager/Main.cs.Net Code: SafeHandle System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
          Source: inhPIwYnDIR.exe.0.dr, ATMManager/Main.cs.Net Code: SafeHandle System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_02C6A6A7 pushfd ; retf
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_02C6A6A1 pushfd ; retf
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_02C6A7F7 pushfd ; retf
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_02C6A7FB pushfd ; retf
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_02C6A88B pushfd ; retf
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_02C6A857 pushfd ; retf
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_02C6A85B pushfd ; retf
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_02C6A827 pushfd ; retf
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_02C6A82B pushfd ; retf
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 0_2_02C63E41 push edx; retf
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018BD0D1 push ecx; ret
          Source: initial sampleStatic PE information: section name: .text entropy: 7.9280997837532565
          Source: initial sampleStatic PE information: section name: .text entropy: 7.9280997837532565
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeFile created: C:\Users\user\AppData\Roaming\inhPIwYnDIR.exeJump to dropped file

          Boot Survival

          barindex
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess created: C:\Windows\SysWOW64\schtasks.exe C:\Windows\System32\schtasks.exe" /Create /TN "Updates\inhPIwYnDIR" /XML "C:\Users\user\AppData\Local\Temp\tmpF1DA.tmp
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX

          Malware Analysis System Evasion

          barindex
          Source: Yara matchFile source: 00000000.00000002.265953049.0000000002F62000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000000.00000002.264390802.0000000002D44000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe PID: 5436, type: MEMORYSTR
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.265953049.0000000002F62000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.264390802.0000000002D44000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SBIEDLL.DLL
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.265953049.0000000002F62000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.264390802.0000000002D44000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: KERNEL32.DLL.WINE_GET_UNIX_FILE_NAME
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeRDTSC instruction interceptor: First address: 0000000000409904 second address: 000000000040990A instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeRDTSC instruction interceptor: First address: 0000000000409B7E second address: 0000000000409B84 instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe TID: 5736Thread sleep time: -45877s >= -30000s
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe TID: 5596Thread sleep time: -922337203685477s >= -30000s
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 1640Thread sleep time: -3689348814741908s >= -30000s
          Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01896B90 rdtsc
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeThread delayed: delay time: 922337203685477
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 9307
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeAPI coverage: 0.5 %
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess information queried: ProcessInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeThread delayed: delay time: 45877
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeThread delayed: delay time: 922337203685477
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.264390802.0000000002D44000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: InstallPathJC:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.264390802.0000000002D44000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: vmware
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.264390802.0000000002D44000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMware SVGA II
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.267398169.0000000003F07000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: vmCiFVL8ZR
          Source: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.264390802.0000000002D44000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMWAREDSOFTWARE\VMware, Inc.\VMware Tools
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01896B90 rdtsc
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess token adjusted: Debug
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: Debug
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188C182 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189A185 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868190 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186519E mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186519E mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01894190 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192A189 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192A189 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018761A7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018761A7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018761A7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018761A7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0193F1B5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0193F1B5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018961A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018961A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E51BE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E51BE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E51BE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E51BE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187C1C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019231DC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019231DC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019231DC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019231DC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019231DC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019231DC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019231DC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019231DC mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019231DC mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019231DC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019231DC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019231DC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019231DC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018631E0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018F41E8 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186B1E1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186B1E1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186B1E1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188D1EF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01869100 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01869100 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01869100 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01870100 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01870100 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01870100 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01884120 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01884120 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01884120 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01884120 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01884120 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189513A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189513A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01863138 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186B171 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186B171 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01869080 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186B080 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A90AF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018920A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018920A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018920A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018920A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018920A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018920A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189F0BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189F0BF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189F0BF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018670C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018670C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192B0C7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192B0C7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018640E1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018640E1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018640E1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019260F5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019260F5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019260F5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019260F5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01934015 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01934015 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189701D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189701D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189701D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189701D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189701D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189701D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018F3019 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E7016 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E7016 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E7016 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189002D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189002D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189002D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189002D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189002D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01894020 mov edi, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187B02A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187B02A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187B02A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187B02A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01867057 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01865050 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01865050 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01865050 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01880050 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01880050 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01922073 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01931074 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189138B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189138B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189138B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0191D380 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192138A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189B390 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01892397 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E53CA mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E53CA mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018953C5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018903E2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018903E2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018903E2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018903E2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018903E2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018903E2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019123E3 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019123E3 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019123E3 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192131B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186F358 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018F6365 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018F6365 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018F6365 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187F370 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187F370 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187F370 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192129A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189D294 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189D294 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018652A5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018652A5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018652A5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018652A5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018652A5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018762A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018762A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018762A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018762A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018912BD mov esi, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018912BD mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018912BD mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018612D4 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192B2E8 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192B2E8 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192B2E8 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192B2E8 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01865210 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01865210 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01865210 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01865210 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186B233 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186B233 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01921229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B236 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B236 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B236 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B236 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B236 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B236 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868239 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868239 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868239 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01869240 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01869240 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01869240 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01869240 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018F4257 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A927A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0191B260 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0191B260 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01892581 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01892581 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01892581 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01892581 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192B581 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192B581 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192B581 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192B581 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01863591 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018935A1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018965A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018965A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018965A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019305AC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019305AC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018615C1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018995EC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187D5E0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187D5E0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018695F0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018695F0 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01923518 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01923518 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01923518 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01869515 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186751A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186751A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186751A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186751A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192E539 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189F527 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189F527 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189F527 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018EA537 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186B540 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186B540 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186354C mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186354C mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E3540 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188C577 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188C577 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01924496 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01924496 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01924496 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01924496 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01924496 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01924496 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01924496 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01924496 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01924496 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01924496 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01924496 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01924496 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01924496 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01861480 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187849B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186649B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186649B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018714A9 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018714A9 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018F34A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018F34A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018F34A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018734B1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018734B1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189D4B0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018F64B5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018F64B5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019214FB mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018984E0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018984E0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018984E0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018984E0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018984E0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018984E0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868410 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0193740D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0193740D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0193740D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187B433 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187B433 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187B433 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01882430 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01882430 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01864439 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189A44B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01938450 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01869450 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018FC450 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018FC450 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868466 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868466 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188746D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01878794 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E7794 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E7794 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E7794 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019217D2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189D7CA mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189D7CA mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019387CF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018937EB mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018937EB mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018937EB mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018937EB mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018937EB mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018937EB mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018937EB mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018897ED mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018897ED mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018897ED mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018897ED mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018897ED mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018897ED mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018897ED mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A37F5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189A70E mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189A70E mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189C707 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189C707 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189C707 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01894710 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189D715 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189D715 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0193070D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0193070D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188F716 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B73D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B73D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01866730 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01866730 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01866730 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189E730 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01921751 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186A745 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868760 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868760 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868760 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868760 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868760 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868760 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868760 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868760 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868760 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01868760 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188E760 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188E760 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019256B6 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019256B6 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018686A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E46A7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018936CC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018906C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018906C0 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018906C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018906C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018906C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018906C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018906C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018906C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018906C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018906C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018906C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018906C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018906C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018776E2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018916E0 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186C600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186C600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186C600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01885600 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189A61C mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189A61C mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01921608 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01861618 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186E620 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01897620 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01897620 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01897620 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01897620 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01897620 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01897620 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187B62E mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187B62E mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E5623 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E5623 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E5623 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E5623 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E5623 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E5623 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E5623 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E5623 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E5623 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189C63D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186A63B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186A63B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018F6652 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0187766D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01884670 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01884670 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01884670 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01884670 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186B990 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01892990 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E69A6 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018999BC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019249A4 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019249A4 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019249A4 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019249A4 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189C9BF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0189C9BF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018899BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018899BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018899BF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018899BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018899BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018899BF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018899BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018899BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018899BF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018899BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018899BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018899BF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018799C7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018799C7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018799C7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018799C7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019219D8 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_019389E7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01921951 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B944 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0188B944 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186395E mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186395E mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0186C962 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_0192E962 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01938966 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01863880 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_01863880 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E3884 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018E3884 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018728AE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018728AE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018728AE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018728AE mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018728AE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018728AE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018978A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018978A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018978A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018978A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018978A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018978A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018978A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018978A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018978A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018678D6 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018678D6 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018678D6 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess queried: DebugPort
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeCode function: 9_2_018A96E0 NtFreeVirtualMemory,LdrInitializeThunk,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeMemory allocated: page read and write | page guard

          HIPS / PFW / Operating System Protection Evasion

          barindex
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeMemory written: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe base: 400000 value starts with: 4D5A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\inhPIwYnDIR.exe
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\inhPIwYnDIR.exe
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\inhPIwYnDIR.exe
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess created: C:\Windows\SysWOW64\schtasks.exe C:\Windows\System32\schtasks.exe" /Create /TN "Updates\inhPIwYnDIR" /XML "C:\Users\user\AppData\Local\Temp\tmpF1DA.tmp
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ariali.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\arialbd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\arialbi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ARIALN.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ariblk.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ARIALNI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ARIALNB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ARIALNBI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\calibri.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\calibril.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\consola.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\consolai.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\consolab.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\consolaz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\seguisli.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\seguili.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\seguisbi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\seguibl.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\seguibli.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\seguiemj.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\PRISTINA.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\PAPYRUS.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\MISTRAL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LHANDW.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\OUTLOOK.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\CALIFR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LBRITE.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LBRITED.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LCALLIG.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\MAGNETOB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\MATURASC.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\STENCIL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\VIVALDII.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\VLADIMIR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LATINWD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\TCM_____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\TCMI____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\TCB_____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\TCCM____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\TCCEB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ROCKI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ROCKEB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ROCKBI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ROCCB___.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\PERTIBD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\PERI____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\PALSCRI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\MAIAN.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LTYPEB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LTYPEBO.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\LSANSDI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GILBI___.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\CURLZ___.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\CALISTI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\CALISTB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\CALISTBI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\marlett.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Security\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-ds-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-base-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-base-Package~31bf3856ad364e35~amd64~en-US~10.0.17134.1.cat VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Management-Powershell-Group-WOW64-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Windows-Defender-Management-Powershell-Group-WOW64-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
          Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: 9.0.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3d77138.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3cd9930.6.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000000.00000002.266377783.0000000003CD1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: 9.0.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3d77138.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.3cd9930.6.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000000.00000002.266377783.0000000003CD1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
          Valid Accounts1
          Scheduled Task/Job
          1
          Scheduled Task/Job
          111
          Process Injection
          1
          Masquerading
          OS Credential Dumping221
          Security Software Discovery
          Remote Services11
          Archive Collected Data
          Exfiltration Over Other Network Medium1
          Encrypted Channel
          Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
          Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
          Scheduled Task/Job
          11
          Disable or Modify Tools
          LSASS Memory1
          Process Discovery
          Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
          Application Layer Protocol
          Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
          Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)31
          Virtualization/Sandbox Evasion
          Security Account Manager31
          Virtualization/Sandbox Evasion
          SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
          Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)111
          Process Injection
          NTDS1
          Application Window Discovery
          Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
          Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script11
          Deobfuscate/Decode Files or Information
          LSA Secrets1
          File and Directory Discovery
          SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
          Replication Through Removable MediaLaunchdRc.commonRc.common3
          Obfuscated Files or Information
          Cached Domain Credentials112
          System Information Discovery
          VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
          External Remote ServicesScheduled TaskStartup ItemsStartup Items13
          Software Packing
          DCSyncNetwork SniffingWindows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Is Windows Process
          • Number of created Registry Values
          • Number of created Files
          • Visual Basic
          • Delphi
          • Java
          • .Net C# or VB.NET
          • C, C++ or other language
          • Is malicious
          • Internet
          behaviorgraph top1 signatures2 2 Behavior Graph ID: 680727 Sample: SecuriteInfo.com.W32.AIDete... Startdate: 09/08/2022 Architecture: WINDOWS Score: 100 31 Malicious sample detected (through community Yara rule) 2->31 33 Antivirus detection for URL or domain 2->33 35 Multi AV Scanner detection for submitted file 2->35 37 7 other signatures 2->37 7 SecuriteInfo.com.W32.AIDetectNet.01.24075.exe 7 2->7         started        process3 file4 23 C:\Users\user\AppData\...\inhPIwYnDIR.exe, PE32 7->23 dropped 25 C:\Users\...\inhPIwYnDIR.exe:Zone.Identifier, ASCII 7->25 dropped 27 C:\Users\user\AppData\Local\...\tmpF1DA.tmp, XML 7->27 dropped 29 SecuriteInfo.com.W...et.01.24075.exe.log, ASCII 7->29 dropped 39 Uses schtasks.exe or at.exe to add and modify task schedules 7->39 41 Adds a directory exclusion to Windows Defender 7->41 43 Tries to detect virtualization through RDTSC time measurements 7->43 45 Injects a PE file into a foreign processes 7->45 11 powershell.exe 23 7->11         started        13 schtasks.exe 1 7->13         started        15 SecuriteInfo.com.W32.AIDetectNet.01.24075.exe 7->15         started        17 SecuriteInfo.com.W32.AIDetectNet.01.24075.exe 7->17         started        signatures5 process6 process7 19 conhost.exe 11->19         started        21 conhost.exe 13->21         started       

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          SecuriteInfo.com.W32.AIDetectNet.01.24075.exe24%VirustotalBrowse
          SecuriteInfo.com.W32.AIDetectNet.01.24075.exe100%Joe Sandbox ML
          SourceDetectionScannerLabelLink
          C:\Users\user\AppData\Roaming\inhPIwYnDIR.exe100%Joe Sandbox ML
          SourceDetectionScannerLabelLinkDownload
          9.0.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe.400000.0.unpack100%AviraTR/Crypt.ZPACK.GenDownload File
          No Antivirus matches
          SourceDetectionScannerLabelLink
          http://www.fontbureau.comalsa0%URL Reputationsafe
          http://www.sajatypeworks.com00%Avira URL Cloudsafe
          http://www.carterandcone.comn-u0%URL Reputationsafe
          http://www.jiyu-kobo.co.jp/jp/B0%URL Reputationsafe
          http://www.founder.com.cn/cn/bThe0%URL Reputationsafe
          http://www.jiyu-kobo.co.jp/jp//0%URL Reputationsafe
          http://www.tiro.com0%URL Reputationsafe
          http://www.jiyu-kobo.co.jp/a-d50%Avira URL Cloudsafe
          http://www.goodfont.co.kr0%URL Reputationsafe
          http://www.carterandcone.com0%URL Reputationsafe
          http://www.tiro.comB0%Avira URL Cloudsafe
          http://www.carterandcone.com.0%URL Reputationsafe
          http://www.zhongyicts.com.cnt-b0%Avira URL Cloudsafe
          http://www.sajatypeworks.com0%URL Reputationsafe
          http://www.typography.netD0%URL Reputationsafe
          http://www.founder.com.cn/cn/cThe0%URL Reputationsafe
          http://www.fontbureau.comony0%URL Reputationsafe
          http://www.galapagosdesign.com/staff/dennis.htm0%URL Reputationsafe
          http://fontfabrik.com0%URL Reputationsafe
          http://www.jiyu-kobo.co.jp/80%URL Reputationsafe
          http://www.carterandcone.comead#0%Avira URL Cloudsafe
          http://www.jiyu-kobo.co.jp//0%URL Reputationsafe
          http://www.fontbureau.comcom0%URL Reputationsafe
          http://www.founder.com.cn/cn/_0%Avira URL Cloudsafe
          http://www.urwpp.de50%Avira URL Cloudsafe
          www.josephfoodbank.com/ck12/100%Avira URL Cloudmalware
          http://www.carterandcone.comR0%URL Reputationsafe
          http://www.galapagosdesign.com/DPlease0%URL Reputationsafe
          http://www.fontbureau.com90%URL Reputationsafe
          http://www.urwpp.de)0%Avira URL Cloudsafe
          http://www.fontbureau.comicomK0%Avira URL Cloudsafe
          http://www.sandoll.co.kr0%URL Reputationsafe
          http://www.sajatypeworks.coma0%URL Reputationsafe
          http://www.jiyu-kobo.co.jp/jp/T0%URL Reputationsafe
          http://www.sajatypeworks.comtu0%Avira URL Cloudsafe
          http://www.urwpp.deDPlease0%URL Reputationsafe
          http://www.urwpp.de0%URL Reputationsafe
          http://www.zhongyicts.com.cn0%URL Reputationsafe
          http://www.sajatypeworks.come0%URL Reputationsafe
          http://www.sakkal.com0%URL Reputationsafe
          http://www.sakkal.comX0%URL Reputationsafe
          http://www.fontbureau.comR.TTF0%URL Reputationsafe
          http://www.founder.com.cn/cntoi0%Avira URL Cloudsafe
          http://www.carterandcone.comt-pA0%Avira URL Cloudsafe
          http://www.carterandcone.comtig0%URL Reputationsafe
          http://www.galapagosdesign.com/staff/dennis.htmZTi0%Avira URL Cloudsafe
          http://www.galapagosdesign.com/0%URL Reputationsafe
          http://www.fontbureau.comK0%Avira URL Cloudsafe
          http://www.fontbureau.com.TTFT0%Avira URL Cloudsafe
          http://www.fontbureau.comF0%URL Reputationsafe
          http://www.jiyu-kobo.co.jp/T0%URL Reputationsafe
          http://www.tiro.comslnt0%URL Reputationsafe
          http://www.carterandcone.comTC0%URL Reputationsafe
          http://www.carterandcone.comX0%URL Reputationsafe
          http://www.fontbureau.comT0%Avira URL Cloudsafe
          http://www.carterandcone.comcn0%Avira URL Cloudsafe
          http://www.jiyu-kobo.co.jp/K0%URL Reputationsafe
          http://www.fontbureau.comB.TTFy0%Avira URL Cloudsafe
          http://www.carterandcone.comrr:0%Avira URL Cloudsafe
          http://www.jiyu-kobo.co.jp/jp/0%URL Reputationsafe
          http://www.fontbureau.coma0%URL Reputationsafe
          http://www.jiyu-kobo.co.jp/B0%URL Reputationsafe
          http://en.wikip0%URL Reputationsafe
          http://www.fontbureau.comd0%URL Reputationsafe
          http://www.fontbureau.come.com0%URL Reputationsafe
          http://www.jiyu-kobo.co.jp/jp/y0%URL Reputationsafe
          http://www.carterandcone.comm0%URL Reputationsafe
          http://www.carterandcone.coml0%URL Reputationsafe
          http://www.carterandcone.comk0%URL Reputationsafe
          http://www.founder.com.cn/cn/0%URL Reputationsafe
          http://www.jiyu-kobo.co.jp/y0%URL Reputationsafe
          http://www.fontbureau.comW.TTF50%Avira URL Cloudsafe
          http://www.founder.com.cn/cn0%URL Reputationsafe
          http://www.fontbureau.comtalik0%Avira URL Cloudsafe
          http://www.fontbureau.comn0%URL Reputationsafe
          http://www.jiyu-kobo.co.jp/0%URL Reputationsafe
          http://www.carterandcone.comona0%URL Reputationsafe
          http://www.zhongyicts.com.cno.0%URL Reputationsafe
          http://www.fontbureau.comitu0%URL Reputationsafe
          http://www.fontbureau.comalic0%URL Reputationsafe
          http://www.carterandcone.comncy0%URL Reputationsafe
          http://www.urwpp.dea0%URL Reputationsafe
          http://www.fontbureau.comFn0%Avira URL Cloudsafe
          http://www.founder.com.cn/cn%0%URL Reputationsafe
          No contacted domains info
          NameMaliciousAntivirus DetectionReputation
          www.josephfoodbank.com/ck12/true
          • Avira URL Cloud: malware
          low
          NameSourceMaliciousAntivirus DetectionReputation
          http://www.fontbureau.comalsaSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236117754.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236392198.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236347292.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236031937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236493830.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236246817.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236168084.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236211639.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236319656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236418829.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236368072.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236570276.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236458188.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
          • URL Reputation: safe
          unknown
          http://www.fontbureau.com/designersGSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
            high
            http://www.sajatypeworks.com0SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228876459.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228858447.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228729579.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228908013.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228706179.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228754890.0000000005C0B000.00000004.00000800.00020000.00000000.sdmpfalse
            • Avira URL Cloud: safe
            unknown
            http://www.carterandcone.comn-uSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231256409.0000000005C20000.00000004.00000800.00020000.00000000.sdmpfalse
            • URL Reputation: safe
            unknown
            http://www.jiyu-kobo.co.jp/jp/BSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232544689.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232471880.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232417223.0000000005C18000.00000004.00000800.00020000.00000000.sdmpfalse
            • URL Reputation: safe
            unknown
            http://www.fontbureau.com/designers/?SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
              high
              http://www.founder.com.cn/cn/bTheSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://www.fontbureau.com/designers?SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
                high
                http://www.jiyu-kobo.co.jp/jp//SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232388258.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232471880.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232417223.0000000005C18000.00000004.00000800.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                unknown
                http://www.tiro.comSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231600471.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                unknown
                http://www.jiyu-kobo.co.jp/a-d5SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232544689.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232943240.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232969656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232471880.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232867696.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232417223.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232640563.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232720289.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232999954.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232913704.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232828269.0000000005C19000.00000004.00000800.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                http://www.fontbureau.com/designersSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
                  high
                  http://www.goodfont.co.krSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.carterandcone.comSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231377753.0000000005C1D000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231198964.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231600471.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231239007.0000000005C20000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.tiro.comBSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231600471.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://www.carterandcone.com.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231041899.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231077425.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231062729.0000000005C19000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.zhongyicts.com.cnt-bSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231041899.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231077425.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231018559.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231683857.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231062729.0000000005C19000.00000004.00000800.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://www.sajatypeworks.comSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228876459.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228858447.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228729579.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228908013.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228706179.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228754890.0000000005C0B000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.typography.netDSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.founder.com.cn/cn/cTheSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.fontbureau.comonySecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234239765.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.galapagosdesign.com/staff/dennis.htmSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://fontfabrik.comSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.jiyu-kobo.co.jp/8SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232544689.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232943240.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232969656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232180963.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232388258.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232471880.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232867696.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232417223.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232640563.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232720289.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232999954.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232913704.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232344057.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232141879.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232828269.0000000005C19000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.carterandcone.comead#SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231446583.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231476574.0000000005C1D000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231356394.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231426384.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231377753.0000000005C1D000.00000004.00000800.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://www.jiyu-kobo.co.jp//SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232544689.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232867696.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232640563.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232720289.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232344057.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232828269.0000000005C19000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.fontbureau.comcomSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236117754.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236392198.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235729648.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236347292.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235690463.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236031937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236493830.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235781420.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236246817.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236168084.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236211639.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236319656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236418829.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235955510.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236368072.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236570276.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235997702.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236458188.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235912222.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.founder.com.cn/cn/_SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230812104.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230786348.0000000005C18000.00000004.00000800.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://www.urwpp.de5SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234239765.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234103394.0000000005C1D000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234067778.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234203952.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234131522.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://www.carterandcone.comRSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231249662.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231211075.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231189973.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231284013.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231231688.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231307976.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231266555.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.galapagosdesign.com/DPleaseSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.fontbureau.com9SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234239765.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.urwpp.de)SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236246817.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236319656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  low
                  http://www.fontbureau.comicomKSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239277378.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239586438.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269173777.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239497582.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239309017.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239397211.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://www.fonts.comSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
                    high
                    http://www.sandoll.co.krSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
                    • URL Reputation: safe
                    unknown
                    http://www.sajatypeworks.comaSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228876459.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228858447.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228729579.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228908013.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228706179.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228754890.0000000005C0B000.00000004.00000800.00020000.00000000.sdmpfalse
                    • URL Reputation: safe
                    unknown
                    http://www.jiyu-kobo.co.jp/jp/TSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232471880.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232417223.0000000005C18000.00000004.00000800.00020000.00000000.sdmpfalse
                    • URL Reputation: safe
                    unknown
                    http://www.sajatypeworks.comtuSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228876459.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228858447.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228729579.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228908013.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228706179.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228754890.0000000005C0B000.00000004.00000800.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://www.urwpp.deDPleaseSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
                    • URL Reputation: safe
                    unknown
                    http://www.urwpp.deSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236246817.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236319656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236418829.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236368072.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234131522.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                    • URL Reputation: safe
                    unknown
                    http://www.zhongyicts.com.cnSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231041899.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231077425.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231018559.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231683857.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231062729.0000000005C19000.00000004.00000800.00020000.00000000.sdmpfalse
                    • URL Reputation: safe
                    unknown
                    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.265953049.0000000002F62000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.264390802.0000000002D44000.00000004.00000800.00020000.00000000.sdmpfalse
                      high
                      http://www.sajatypeworks.comeSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228876459.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228858447.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228729579.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228908013.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228706179.0000000005C0B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.228754890.0000000005C0B000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.sakkal.comSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232867696.0000000005C19000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.sakkal.comXSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232867696.0000000005C19000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.fontbureau.comR.TTFSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235203989.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235272067.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235322022.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235401265.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235427394.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235145530.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.founder.com.cn/cntoiSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230663964.0000000005C18000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.carterandcone.comt-pASecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231077425.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231683857.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231062729.0000000005C19000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.carterandcone.comtigSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231538257.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231558138.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231609757.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231578595.0000000005C20000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.galapagosdesign.com/staff/dennis.htmZTiSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.261253820.0000000005BF0000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.apache.org/licenses/LICENSE-2.0SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
                        high
                        http://www.fontbureau.comSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235460068.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234816097.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235203989.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236117754.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236392198.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235729648.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236347292.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234382164.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234698937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234964795.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235690463.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235272067.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236031937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235322022.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236493830.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235781420.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236246817.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236168084.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235535126.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234773422.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                          high
                          http://www.galapagosdesign.com/SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.237292361.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.fontbureau.comKSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234382164.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234270662.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234317595.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://www.fontbureau.com.TTFTSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236117754.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235729648.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236031937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235781420.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235955510.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235997702.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235912222.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://www.fontbureau.comFSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235203989.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236117754.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236392198.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235729648.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236347292.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235272067.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236031937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235322022.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236493830.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236246817.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236168084.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235401265.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235427394.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236211639.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236319656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236418829.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236368072.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235145530.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236570276.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235024440.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236458188.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.jiyu-kobo.co.jp/TSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232544689.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232180963.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232388258.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232867696.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232640563.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232720289.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232344057.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232141879.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232828269.0000000005C19000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.tiro.comslntSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231683857.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231600471.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.carterandcone.comTCSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231538257.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231558138.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231609757.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231503175.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231513867.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231578595.0000000005C20000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.carterandcone.comXSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231609757.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231578595.0000000005C20000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.fontbureau.comTSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236392198.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236347292.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236246817.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236168084.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236211639.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236319656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236418829.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236368072.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236458188.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://www.carterandcone.comcnSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231169117.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231219511.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231198964.0000000005C20000.00000004.00000800.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://www.jiyu-kobo.co.jp/KSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232544689.0000000005C18000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.fontbureau.comB.TTFySecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239586438.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269173777.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239497582.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239309017.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239397211.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://www.carterandcone.comrr:SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231446583.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231476574.0000000005C1D000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231426384.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231377753.0000000005C1D000.00000004.00000800.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://www.jiyu-kobo.co.jp/jp/SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232544689.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232943240.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232969656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232180963.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232388258.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232471880.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232867696.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232417223.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232640563.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232720289.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232089772.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232999954.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232913704.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232344057.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232141879.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232828269.0000000005C19000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.fontbureau.comaSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239277378.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239586438.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269173777.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239497582.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239309017.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239397211.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.jiyu-kobo.co.jp/BSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232388258.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://en.wikipSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230679142.0000000005C20000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.fontbureau.comdSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234617673.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.fontbureau.come.comSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234816097.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235203989.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234698937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234617673.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234964795.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234773422.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235145530.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235024440.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234902484.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234850708.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.jiyu-kobo.co.jp/jp/ySecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232544689.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232867696.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232640563.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232720289.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232828269.0000000005C19000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.carterandcone.commSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231570209.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231325851.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231249662.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231211075.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231528192.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231446583.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231343075.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231494427.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231284013.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231231688.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231307976.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231356394.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231426384.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231513867.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231266555.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231550741.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.carterandcone.comlSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231169117.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231219511.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231256409.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231609757.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231273161.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231503175.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231455460.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231578595.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231114511.0000000005C1D000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231198964.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231239007.0000000005C20000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.carterandcone.comkSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231570209.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231325851.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231249662.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231211075.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231528192.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231446583.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231189973.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231343075.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231494427.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231284013.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231231688.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231307976.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231356394.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231426384.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231513867.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231266555.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231550741.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231132980.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.founder.com.cn/cn/SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230497918.0000000005C1B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230521856.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230428147.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230366877.0000000005C18000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.jiyu-kobo.co.jp/ySecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232471880.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232417223.0000000005C18000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.fontbureau.com/designers/cabarga.htmlNSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
                            high
                            http://www.fontbureau.comW.TTF5SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235203989.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235272067.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235322022.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235401265.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235427394.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235145530.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235024440.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://www.founder.com.cn/cnSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230812104.0000000005C19000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230645268.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230786348.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230612048.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230663964.0000000005C18000.00000004.00000800.00020000.00000000.sdmpfalse
                            • URL Reputation: safe
                            unknown
                            http://www.fontbureau.com/designers/frere-user.htmlSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
                              high
                              http://www.fontbureau.comtalikSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234382164.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234270662.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234317595.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.carterandcone.comxSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231570209.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231528192.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231550741.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231600471.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                                unknown
                                http://www.fontbureau.comnSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.239309017.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                                • URL Reputation: safe
                                unknown
                                http://www.jiyu-kobo.co.jp/SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.232828269.0000000005C19000.00000004.00000800.00020000.00000000.sdmpfalse
                                • URL Reputation: safe
                                unknown
                                http://www.carterandcone.comonaSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231513867.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                                • URL Reputation: safe
                                unknown
                                http://www.zhongyicts.com.cno.SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231018559.0000000005C18000.00000004.00000800.00020000.00000000.sdmpfalse
                                • URL Reputation: safe
                                unknown
                                http://www.fontbureau.com/designers8SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000002.269353830.0000000006E02000.00000004.00000800.00020000.00000000.sdmpfalse
                                  high
                                  http://www.fontbureau.comituSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235571385.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                                  • URL Reputation: safe
                                  unknown
                                  http://www.fontbureau.comalicSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234816097.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235203989.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234698937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234964795.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235272067.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235322022.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234773422.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235401265.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235427394.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235145530.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235024440.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234902484.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234850708.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                                  • URL Reputation: safe
                                  unknown
                                  http://www.carterandcone.comncySecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231538257.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231482683.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231558138.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231609757.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231503175.0000000005C20000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231513867.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.231578595.0000000005C20000.00000004.00000800.00020000.00000000.sdmpfalse
                                  • URL Reputation: safe
                                  unknown
                                  http://www.urwpp.deaSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234103394.0000000005C1D000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234067778.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.234131522.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                                  • URL Reputation: safe
                                  unknown
                                  http://www.fontbureau.comFnSecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236117754.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236392198.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235729648.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236347292.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235690463.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236031937.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236493830.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235781420.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236246817.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236168084.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236211639.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236319656.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236418829.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235955510.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236368072.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236570276.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235997702.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.236458188.0000000005C1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.235912222.0000000005C1A000.00000004.00000800.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://www.founder.com.cn/cn%SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230645268.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230786348.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230612048.0000000005C18000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.W32.AIDetectNet.01.24075.exe, 00000000.00000003.230663964.0000000005C18000.00000004.00000800.00020000.00000000.sdmpfalse
                                  • URL Reputation: safe
                                  unknown
                                  No contacted IP infos
                                  Joe Sandbox Version:35.0.0 Citrine
                                  Analysis ID:680727
                                  Start date and time: 09/08/202204:30:062022-08-09 04:30:06 +02:00
                                  Joe Sandbox Product:CloudBasic
                                  Overall analysis duration:0h 7m 36s
                                  Hypervisor based Inspection enabled:false
                                  Report type:light
                                  Sample file name:SecuriteInfo.com.W32.AIDetectNet.01.24075.5367 (renamed file extension from 5367 to exe)
                                  Cookbook file name:default.jbs
                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                  Number of analysed new started processes analysed:33
                                  Number of new started drivers analysed:0
                                  Number of existing processes analysed:0
                                  Number of existing drivers analysed:0
                                  Number of injected processes analysed:0
                                  Technologies:
                                  • HCA enabled
                                  • EGA enabled
                                  • HDC enabled
                                  • AMSI enabled
                                  Analysis Mode:default
                                  Analysis stop reason:Timeout
                                  Detection:MAL
                                  Classification:mal100.troj.evad.winEXE@11/8@0/0
                                  EGA Information:
                                  • Successful, ratio: 100%
                                  HDC Information:
                                  • Successful, ratio: 100% (good quality ratio 90.8%)
                                  • Quality average: 75.4%
                                  • Quality standard deviation: 30.7%
                                  HCA Information:
                                  • Successful, ratio: 95%
                                  • Number of executed functions: 0
                                  • Number of non-executed functions: 0
                                  Cookbook Comments:
                                  • Adjust boot time
                                  • Enable AMSI
                                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, WmiPrvSE.exe, svchost.exe, wuapihost.exe
                                  • Excluded IPs from analysis (whitelisted): 23.211.6.115
                                  • Excluded domains from analysis (whitelisted): www.bing.com, ris.api.iris.microsoft.com, e12564.dspb.akamaiedge.net, fs.microsoft.com, login.live.com, store-images.s-microsoft.com, sls.update.microsoft.com, ctldl.windowsupdate.com, store-images.s-microsoft.com-c.edgekey.net, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, arc.msn.com
                                  • Not all processes where analyzed, report is missing behavior information
                                  • Report creation exceeded maximum time and may have missing disassembly code information.
                                  • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                  • Report size getting too big, too many NtOpenKeyEx calls found.
                                  • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                  • Report size getting too big, too many NtQueryValueKey calls found.
                                  TimeTypeDescription
                                  04:31:12API Interceptor1x Sleep call for process: SecuriteInfo.com.W32.AIDetectNet.01.24075.exe modified
                                  04:31:17API Interceptor41x Sleep call for process: powershell.exe modified
                                  No context
                                  No context
                                  No context
                                  No context
                                  No context
                                  Process:C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
                                  File Type:ASCII text, with CRLF line terminators
                                  Category:modified
                                  Size (bytes):1308
                                  Entropy (8bit):5.345811588615766
                                  Encrypted:false
                                  SSDEEP:24:MLUE4K5E4Ks2E1qE4qXKDE4KhK3VZ9pKhPKIE4oKFKHKoZAE4Kzr7FE4x84FsXE8:MIHK5HKXE1qHiYHKhQnoPtHoxHhAHKzu
                                  MD5:2E016B886BDB8389D2DD0867BE55F87B
                                  SHA1:25D28EF2ACBB41764571E06E11BF4C05DD0E2F8B
                                  SHA-256:1D037CF00A8849E6866603297F85D3DABE09535E72EDD2636FB7D0F6C7DA3427
                                  SHA-512:C100729153954328AA2A77EECB2A3CBD03CB7E8E23D736000F890B17AAA50BA87745E30FB9E2B0D61E16DCA45694C79B4CE09B9F4475220BEB38CAEA546CFC2A
                                  Malicious:true
                                  Reputation:high, very likely benign file
                                  Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\4f0a7eefa3cd3e0ba98b5ebddbbc72e6\System.ni.dll",0..2,"System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\f1d8480152e0da9a60ad49c6d16a3b6d\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\8d67d92724ba494b6c7fd089d6f25b48\System.Configuration.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\b219d4630d26b88041b59c21
                                  Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):22284
                                  Entropy (8bit):5.601136008439
                                  Encrypted:false
                                  SSDEEP:384:4tCDqG0BtZL2ZRxonRnw4KnAjultI2b7E9gxSJ3xe1BMrmbZ1AV7oWvc64I+iq0:WLKNoJw4KACltJrxctq4Ks
                                  MD5:55E76F8988E36C2B7CF80C5AD82C76F0
                                  SHA1:ECF01B0C42BDB13A298BF67F16550937899A28CA
                                  SHA-256:AE7F2CC96275F95D13E8806EAC42CFBB841ED2D63B738007BF63E783002E4153
                                  SHA-512:FF4475F28C0F4A1DE41454F757C35F2D37A5995C110482873F4F798457BE210499B0BFB824FA18609183F4F8811BC4387F24D75F0E6E3E5A781926DDB3E1B70D
                                  Malicious:false
                                  Reputation:low
                                  Preview:@...e...........|.........Y.N.D.#...@................@..........H...............<@.^.L."My...:R..... .Microsoft.PowerShell.ConsoleHostD...............fZve...F.....x.)........System.Management.Automation4...............[...{a.C..%6..h.........System.Core.0...............G-.o...A...4B..........System..4................Zg5..:O..g..q..........System.Xml..L...............7.....J@......~.......#.Microsoft.Management.Infrastructure.8................'....L..}............System.Numerics.@................Lo...QN......<Q........System.DirectoryServices<................H..QN.Y.f............System.Management...4....................].D.E.....#.......System.Data.H................. ....H..m)aUu.........Microsoft.PowerShell.Security...<.................~.[L.D.Z.>..m.........System.Transactions.<................):gK..G...$.1.q........System.ConfigurationP................./.C..J..%...].......%.Microsoft.PowerShell.Commands.Utility...D..................-.D.F.<;.nt.1........System.Configuration.Ins
                                  Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                  File Type:very short file (no magic)
                                  Category:dropped
                                  Size (bytes):1
                                  Entropy (8bit):0.0
                                  Encrypted:false
                                  SSDEEP:3:U:U
                                  MD5:C4CA4238A0B923820DCC509A6F75849B
                                  SHA1:356A192B7913B04C54574D18C28D46E6395428AB
                                  SHA-256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
                                  SHA-512:4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A
                                  Malicious:false
                                  Reputation:high, very likely benign file
                                  Preview:1
                                  Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                  File Type:very short file (no magic)
                                  Category:dropped
                                  Size (bytes):1
                                  Entropy (8bit):0.0
                                  Encrypted:false
                                  SSDEEP:3:U:U
                                  MD5:C4CA4238A0B923820DCC509A6F75849B
                                  SHA1:356A192B7913B04C54574D18C28D46E6395428AB
                                  SHA-256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
                                  SHA-512:4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A
                                  Malicious:false
                                  Reputation:high, very likely benign file
                                  Preview:1
                                  Process:C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
                                  File Type:XML 1.0 document, ASCII text
                                  Category:dropped
                                  Size (bytes):1598
                                  Entropy (8bit):5.1373713173309135
                                  Encrypted:false
                                  SSDEEP:24:2di4+S2qh/S1KTy1moCUnrKMhEMOFGpwOzNgU3ODOiIQRvh7hwrgXuNta0xvn:cgeKwYrFdOFzOzN33ODOiDdKrsuTjv
                                  MD5:87F13D1E52470630E99537D13DAFACF8
                                  SHA1:53917E3ED8A59E7DD2B4DB5DA607789BE0CBA250
                                  SHA-256:DC144BF5C9AD89D7820BA81639DFAB2C9CA9091A96E4BD34A4F5990001736702
                                  SHA-512:7B8D6A638B232218272F3EB3F59536EA5377F84E2ADB433DF5F43BFE237184B248FB8EEDA9CE4B954E329683EA43C0BC842F25AB2C2DB382B6E9AC40C9BA3D6A
                                  Malicious:true
                                  Preview:<?xml version="1.0" encoding="UTF-16"?>.<Task version="1.2" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">. <RegistrationInfo>. <Date>2014-10-25T14:27:44.8929027</Date>. <Author>computer\user</Author>. </RegistrationInfo>. <Triggers>. <LogonTrigger>. <Enabled>true</Enabled>. <UserId>computer\user</UserId>. </LogonTrigger>. <RegistrationTrigger>. <Enabled>false</Enabled>. </RegistrationTrigger>. </Triggers>. <Principals>. <Principal id="Author">. <UserId>computer\user</UserId>. <LogonType>InteractiveToken</LogonType>. <RunLevel>LeastPrivilege</RunLevel>. </Principal>. </Principals>. <Settings>. <MultipleInstancesPolicy>StopExisting</MultipleInstancesPolicy>. <DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>. <StopIfGoingOnBatteries>true</StopIfGoingOnBatteries>. <AllowHardTerminate>false</AllowHardTerminate>. <StartWhenAvailable>true</StartWhenAvailable>. <
                                  Process:C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
                                  File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                  Category:dropped
                                  Size (bytes):1095680
                                  Entropy (8bit):7.802530691464413
                                  Encrypted:false
                                  SSDEEP:24576:A/yKZ+uOOOiYGLW9uJhZ1Q7LLOstiumDIDHqnijxOvS:A/yK8uOOOiFLEO71QfLOs0umUzq6xOv
                                  MD5:C021921CD23808CB0E4040D1FCCD30D6
                                  SHA1:3ABB4EB5B6EAE3C088C13698DD54EB06A2B8DE48
                                  SHA-256:FAC0D50307E72DDB6BDDB0865C4053D9A9BB691641A12989594F71F0E6137D1F
                                  SHA-512:9DAAB78A9EBD8C83C73DC08DD39616B2CDDF7290FF2624FD347689D65CB7BE84E22BE0D42283C6B7DB5FF778AF4CD9C3619D99EF701E5A18D4EBCBDF6232E60D
                                  Malicious:true
                                  Antivirus:
                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...^..b..............0...... ......j.... ........@.. ....................................@.....................................O.......8............................................................................ ............... ..H............text...p.... ...................... ..`.rsrc...8...........................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
                                  File Type:ASCII text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):26
                                  Entropy (8bit):3.95006375643621
                                  Encrypted:false
                                  SSDEEP:3:ggPYV:rPYV
                                  MD5:187F488E27DB4AF347237FE461A079AD
                                  SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                                  SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                                  SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                                  Malicious:true
                                  Preview:[ZoneTransfer]....ZoneId=0
                                  Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                  File Type:UTF-8 Unicode (with BOM) text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):5793
                                  Entropy (8bit):5.399009835914265
                                  Encrypted:false
                                  SSDEEP:96:BZrjLNzqDo1ZWZIjLNzqDo1Zos6UjZCjLNzqDo1ZiNkkqZ5:g
                                  MD5:BD68CCF99F20131C0340DF1FF67F1809
                                  SHA1:1619AC634239ACBC1BB60BA495B3658215E467A9
                                  SHA-256:56133B41D5F9D02E4537A022D7A0608C0175C65128D61C60DFCDAD38F5990BA9
                                  SHA-512:55F6D69A7BFFEBF075C368240EC16C7E7B9D3E91599A5C2C692A1C6326B49E22725F7241A058D57DE5A9446FC226669A31483C8459EC8297F0C3137DB2301775
                                  Malicious:false
                                  Preview:.**********************..Windows PowerShell transcript start..Start time: 20220809043117..Username: computer\user..RunAs User: computer\user..Configuration Name: ..Machine: 724536 (Microsoft Windows NT 10.0.17134.0)..Host Application: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Add-MpPreference -ExclusionPath C:\Users\user\AppData\Roaming\inhPIwYnDIR.exe..Process ID: 1892..PSVersion: 5.1.17134.1..PSEdition: Desktop..PSCompatibleVersions: 1.0, 2.0, 3.0, 4.0, 5.0, 5.1.17134.1..BuildVersion: 10.0.17134.1..CLRVersion: 4.0.30319.42000..WSManStackVersion: 3.0..PSRemotingProtocolVersion: 2.3..SerializationVersion: 1.1.0.1..**********************..**********************..Command start time: 20220809043117..**********************..PS>Add-MpPreference -ExclusionPath C:\Users\user\AppData\Roaming\inhPIwYnDIR.exe..**********************..Windows PowerShell transcript start..Start time: 20220809043518..Username: computer\user..RunAs User: computer\jo
                                  File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                  Entropy (8bit):7.802530691464413
                                  TrID:
                                  • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                                  • Win32 Executable (generic) a (10002005/4) 49.78%
                                  • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                                  • Win16/32 Executable Delphi generic (2074/23) 0.01%
                                  • Generic Win/DOS Executable (2004/3) 0.01%
                                  File name:SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
                                  File size:1095680
                                  MD5:c021921cd23808cb0e4040d1fccd30d6
                                  SHA1:3abb4eb5b6eae3c088c13698dd54eb06a2b8de48
                                  SHA256:fac0d50307e72ddb6bddb0865c4053d9a9bb691641a12989594f71f0e6137d1f
                                  SHA512:9daab78a9ebd8c83c73dc08dd39616b2cddf7290ff2624fd347689d65cb7be84e22be0d42283c6b7db5ff778af4cd9c3619d99ef701e5a18d4ebcbdf6232e60d
                                  SSDEEP:24576:A/yKZ+uOOOiYGLW9uJhZ1Q7LLOstiumDIDHqnijxOvS:A/yK8uOOOiFLEO71QfLOs0umUzq6xOv
                                  TLSH:8C35F181A3955721C9692BF8962DEE900BE37EE67439EA1D3DC130F963733920161D2F
                                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...^..b..............0...... ......j.... ........@.. ....................................@................................
                                  Icon Hash:0600242601012000
                                  Entrypoint:0x4fb06a
                                  Entrypoint Section:.text
                                  Digitally signed:false
                                  Imagebase:0x400000
                                  Subsystem:windows gui
                                  Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                  DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                  Time Stamp:0x62F1A65E [Tue Aug 9 00:12:14 2022 UTC]
                                  TLS Callbacks:
                                  CLR (.Net) Version:
                                  OS Version Major:4
                                  OS Version Minor:0
                                  File Version Major:4
                                  File Version Minor:0
                                  Subsystem Version Major:4
                                  Subsystem Version Minor:0
                                  Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                                  Instruction
                                  jmp dword ptr [00402000h]
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  NameVirtual AddressVirtual Size Is in Section
                                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_IMPORT0xfb0180x4f.text
                                  IMAGE_DIRECTORY_ENTRY_RESOURCE0xfc0000x11a38.rsrc
                                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x10e0000xc.reloc
                                  IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                  IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                  NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                  .text0x20000xf90700xf9400False0.8771255171765295data7.9280997837532565IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                  .rsrc0xfc0000x11a380x11c00False0.21326199383802816data3.0571782930957747IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                  .reloc0x10e0000xc0x400False0.025390625data0.05585530805374581IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                  NameRVASizeTypeLanguageCountry
                                  RT_ICON0xfc1600x10828data
                                  RT_GROUP_ICON0x10c9880x14data
                                  RT_GROUP_ICON0x10c99c0x14data
                                  RT_VERSION0x10c9b00x360data
                                  RT_MANIFEST0x10cd100xd25XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF, LF line terminators
                                  DLLImport
                                  mscoree.dll_CorExeMain
                                  No network behavior found
                                  Target ID:0
                                  Start time:04:31:04
                                  Start date:09/08/2022
                                  Path:C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
                                  Wow64 process (32bit):true
                                  Commandline:"C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe"
                                  Imagebase:0x860000
                                  File size:1095680 bytes
                                  MD5 hash:C021921CD23808CB0E4040D1FCCD30D6
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:.Net C# or VB.NET
                                  Yara matches:
                                  • Rule: JoeSecurity_AntiVM_3, Description: Yara detected AntiVM_3, Source: 00000000.00000002.265953049.0000000002F62000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_AntiVM_3, Description: Yara detected AntiVM_3, Source: 00000000.00000002.264390802.0000000002D44000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_FormBook, Description: Yara detected FormBook, Source: 00000000.00000002.266377783.0000000003CD1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                  • Rule: Windows_Trojan_Formbook_1112e116, Description: unknown, Source: 00000000.00000002.266377783.0000000003CD1000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                                  • Rule: Formbook_1, Description: autogenerated rule brought to you by yara-signator, Source: 00000000.00000002.266377783.0000000003CD1000.00000004.00000800.00020000.00000000.sdmp, Author: Felix Bilstein - yara-signator at cocacoding dot com
                                  • Rule: Formbook, Description: detect Formbook in memory, Source: 00000000.00000002.266377783.0000000003CD1000.00000004.00000800.00020000.00000000.sdmp, Author: JPCERT/CC Incident Response Group
                                  Reputation:low

                                  Target ID:4
                                  Start time:04:31:14
                                  Start date:09/08/2022
                                  Path:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                  Wow64 process (32bit):true
                                  Commandline:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\inhPIwYnDIR.exe
                                  Imagebase:0x20000
                                  File size:430592 bytes
                                  MD5 hash:DBA3E6449E97D4E3DF64527EF7012A10
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:.Net C# or VB.NET
                                  Reputation:high

                                  Target ID:5
                                  Start time:04:31:15
                                  Start date:09/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff647620000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high

                                  Target ID:6
                                  Start time:04:31:15
                                  Start date:09/08/2022
                                  Path:C:\Windows\SysWOW64\schtasks.exe
                                  Wow64 process (32bit):true
                                  Commandline:C:\Windows\System32\schtasks.exe" /Create /TN "Updates\inhPIwYnDIR" /XML "C:\Users\user\AppData\Local\Temp\tmpF1DA.tmp
                                  Imagebase:0x940000
                                  File size:185856 bytes
                                  MD5 hash:15FF7D8324231381BAD48A052F85DF04
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high

                                  Target ID:7
                                  Start time:04:31:17
                                  Start date:09/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff647620000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high

                                  Target ID:8
                                  Start time:04:31:18
                                  Start date:09/08/2022
                                  Path:C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
                                  Imagebase:0x160000
                                  File size:1095680 bytes
                                  MD5 hash:C021921CD23808CB0E4040D1FCCD30D6
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:low

                                  Target ID:9
                                  Start time:04:31:19
                                  Start date:09/08/2022
                                  Path:C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
                                  Wow64 process (32bit):true
                                  Commandline:C:\Users\user\Desktop\SecuriteInfo.com.W32.AIDetectNet.01.24075.exe
                                  Imagebase:0xba0000
                                  File size:1095680 bytes
                                  MD5 hash:C021921CD23808CB0E4040D1FCCD30D6
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Yara matches:
                                  • Rule: JoeSecurity_FormBook, Description: Yara detected FormBook, Source: 00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                  • Rule: Windows_Trojan_Formbook_1112e116, Description: unknown, Source: 00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
                                  • Rule: Formbook_1, Description: autogenerated rule brought to you by yara-signator, Source: 00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmp, Author: Felix Bilstein - yara-signator at cocacoding dot com
                                  • Rule: Formbook, Description: detect Formbook in memory, Source: 00000009.00000000.259219665.0000000000401000.00000040.00000400.00020000.00000000.sdmp, Author: JPCERT/CC Incident Response Group
                                  Reputation:low

                                  No disassembly