Source: hfs.exe, 00000008.00000003.1504639466.0000000000732000.00000004.00000020.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1604212828.0000000004962000.00000004.00001000.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1603714019.00000000008A5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: HTTP://TRENTRICHARDSON.COM |
Source: hfs.exe, 00000008.00000003.1504639466.0000000000732000.00000004.00000020.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1604212828.0000000004962000.00000004.00001000.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1603714019.00000000008A5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: HTTP://TRENTRICHARDSON.COM/IMPROMPTU/GPL-LICENSE.TXT |
Source: hfs.exe, 00000008.00000003.1504639466.0000000000732000.00000004.00000020.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1604212828.0000000004962000.00000004.00001000.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1603714019.00000000008A5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: HTTP://TRENTRICHARDSON.COM/IMPROMPTU/MIT-LICENSE.TXT |
Source: hfs.exe, 00000009.00000003.1603800287.000000000089D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: HTTP://WWW.REJE |
Source: hfs.exe, 00000009.00000003.1604212828.0000000004962000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: HTTP://WWW.REJETTO.COM/HFS/ |
Source: hfs.exe, 00000008.00000002.2105720860.0000000000D2A000.00000004.00001000.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1606570097.000000000253A000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://192.168.2.3/ |
Source: hfs.exe, 00000008.00000002.2100836601.000000000019A000.00000004.00000010.00020000.00000000.sdmp | String found in binary or memory: http://192.168.2.3/.3/x |
Source: hfs.exe, 00000009.00000003.1606570097.000000000253A000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://192.168.2.3/.js |
Source: hfs.exe, 00000008.00000002.2102065800.00000000006CD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://192.168.2.3/L |
Source: hfs.exe, 00000008.00000000.1496967069.0000000000597000.00000002.00000001.01000000.00000005.sdmp | String found in binary or memory: http://2ip.ru |
Source: hfs.exe, 00000008.00000000.1496967069.0000000000597000.00000002.00000001.01000000.00000005.sdmp | String found in binary or memory: http://checkip.dyndns.org |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://hfsservice.rejetto.com/ipservices.php |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://hfstest.rejetto.com/?port= |
Source: hfs.exe, 00000008.00000000.1496967069.0000000000597000.00000002.00000001.01000000.00000005.sdmp, hfs.exe, 00000008.00000002.2104806639.0000000000C44000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://jquery.com/ |
Source: hfs.exe, 00000008.00000000.1496967069.0000000000597000.00000002.00000001.01000000.00000005.sdmp, hfs.exe, 00000008.00000002.2104806639.0000000000C44000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://jquery.org/license |
Source: hfs.exe, 00000008.00000000.1496967069.0000000000597000.00000002.00000001.01000000.00000005.sdmp | String found in binary or memory: http://rejetto.webfactional.com/hfs/ip.php |
Source: hfs.exe, 00000008.00000000.1496967069.0000000000597000.00000002.00000001.01000000.00000005.sdmp, hfs.exe, 00000008.00000002.2104806639.0000000000C44000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://sizzlejs.com/ |
Source: hfs.exe, 00000008.00000002.2106879567.0000000004970000.00000004.00001000.00020000.00000000.sdmp, hfs.exe, 00000008.00000000.1496967069.0000000000597000.00000002.00000001.01000000.00000005.sdmp, hfs.exe, 00000009.00000003.1604528294.00000000049C7000.00000004.00001000.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1605338134.0000000002484000.00000004.00001000.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1604212828.0000000004962000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://trentrichardson.com |
Source: hfs.exe, 00000008.00000002.2106879567.0000000004970000.00000004.00001000.00020000.00000000.sdmp, hfs.exe, 00000008.00000000.1496967069.0000000000597000.00000002.00000001.01000000.00000005.sdmp, hfs.exe, 00000009.00000003.1604528294.00000000049C7000.00000004.00001000.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1605338134.0000000002484000.00000004.00001000.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1604212828.0000000004962000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://trentrichardson.com/Impromptu/GPL-LICENSE.txt |
Source: hfs.exe, 00000008.00000002.2106879567.0000000004970000.00000004.00001000.00020000.00000000.sdmp, hfs.exe, 00000008.00000000.1496967069.0000000000597000.00000002.00000001.01000000.00000005.sdmp, hfs.exe, 00000009.00000003.1604528294.00000000049C7000.00000004.00001000.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1605338134.0000000002484000.00000004.00001000.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1604212828.0000000004962000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://trentrichardson.com/Impromptu/MIT-LICENSE.txt |
Source: hfs.exe, 00000008.00000000.1496967069.0000000000597000.00000002.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.alexnolan.net/ip/ |
Source: hfs.exe, 00000008.00000002.2102534464.00000000006F1000.00000004.00000020.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1606850658.0000000000856000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.autoitscript.com/autoit3 |
Source: hfs.exe, 00000008.00000000.1496967069.0000000000597000.00000002.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.canyouseeme.org |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.cjb.net/cgi-bin/dynip.cgi?username= |
Source: hfs.exe, 00000008.00000000.1496967069.0000000000597000.00000002.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.mario-online.com/mio_indirizzo_ip.php |
Source: hfs.exe, 00000008.00000000.1496967069.0000000000597000.00000002.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.melauto.it/public/rejetto/ip.php |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.rejetto.com/forum/ |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.rejetto.com/forum/U |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.rejetto.com/hfs-donate |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.rejetto.com/hfs-donateU |
Source: hfs.exe, 00000009.00000003.1605338134.0000000002484000.00000004.00001000.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1604784665.000000000241A000.00000004.00001000.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1604447474.00000000049B2000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://www.rejetto.com/hfs/ |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.rejetto.com/hfs/U |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.rejetto.com/hfs/guide/ |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.rejetto.com/hfs/guide/U |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.rejetto.com/hfs/guide/intro.html |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.rejetto.com/hfs/guide/intro.htmlU |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.rejetto.com/hfs/hfs.updateinfo.txt |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.rejetto.com/sw/?faq=hfs |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.rejetto.com/sw/?faq=hfsU |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.rejetto.com/sw/license.txt |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.rejetto.com/sw/license.txtU |
Source: hfs.exe, 00000008.00000000.1495709992.0000000000401000.00000020.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.rejetto.com/wiki/?title=HFS:_Event_scripts |
Source: hfs.exe, 00000008.00000000.1496967069.0000000000597000.00000002.00000001.01000000.00000005.sdmp | String found in binary or memory: http://www.whatsmyrealip.com/ |
Source: hfs.exe, 00000008.00000002.2102534464.00000000006F1000.00000004.00000020.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1606850658.0000000000856000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://support.mozilla.org |
Source: hfs.exe, 00000008.00000002.2102534464.00000000006F1000.00000004.00000020.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1606850658.0000000000856000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.mozilla.org |
Source: hfs.exe, 00000008.00000002.2102534464.00000000006F1000.00000004.00000020.00020000.00000000.sdmp, hfs.exe, 00000009.00000003.1606850658.0000000000856000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.mozilla.org/firefox/88.0.1/releasenotes |
Source: unknown | Process created: C:\Users\user\Downloads\sMuqUfejlr\MDE_File_Sample_d0c4192b65e36553f6fd2b83f3123f6ae8380dac\hfs.exe "C:\Users\user\Downloads\sMuqUfejlr\MDE_File_Sample_d0c4192b65e36553f6fd2b83f3123f6ae8380dac\hfs.exe" | |
Source: unknown | Process created: C:\Users\user\Downloads\sMuqUfejlr\MDE_File_Sample_d0c4192b65e36553f6fd2b83f3123f6ae8380dac\hfs.exe "C:\Users\user\Downloads\sMuqUfejlr\MDE_File_Sample_d0c4192b65e36553f6fd2b83f3123f6ae8380dac\hfs.exe" | |
Source: C:\Users\user\Downloads\sMuqUfejlr\MDE_File_Sample_d0c4192b65e36553f6fd2b83f3123f6ae8380dac\hfs.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://localhost/ | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=1800,i,15845607598309569979,15213409677868717559,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 | |
Source: C:\Users\user\Downloads\sMuqUfejlr\MDE_File_Sample_d0c4192b65e36553f6fd2b83f3123f6ae8380dac\hfs.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://localhost/ | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=1800,i,15845607598309569979,15213409677868717559,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |