Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.58.85.196 |
Source: sbuvJk8Zn8.exe, 00000001.00000002.4159148683.0000000002EA1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: xvu3kzsi.rmq.1.dr |
String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: xvu3kzsi.rmq.1.dr |
String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: xvu3kzsi.rmq.1.dr |
String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: xvu3kzsi.rmq.1.dr |
String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: xvu3kzsi.rmq.1.dr |
String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: xvu3kzsi.rmq.1.dr |
String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: xvu3kzsi.rmq.1.dr |
String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: 2kpofmcl.euu.1.dr, znhngz5e.cyk.1.dr |
String found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016 |
Source: sbuvJk8Zn8.exe, 00000001.00000002.4160550193.0000000003F0A000.00000004.00000800.00020000.00000000.sdmp, 2kpofmcl.euu.1.dr, znhngz5e.cyk.1.dr |
String found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016Examples |
Source: 2kpofmcl.euu.1.dr, znhngz5e.cyk.1.dr |
String found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17 |
Source: sbuvJk8Zn8.exe, 00000001.00000002.4160550193.0000000003F0A000.00000004.00000800.00020000.00000000.sdmp, 2kpofmcl.euu.1.dr, znhngz5e.cyk.1.dr |
String found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17Install |
Source: xvu3kzsi.rmq.1.dr |
String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: xvu3kzsi.rmq.1.dr |
String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Code function: 0_2_025C0B12 |
0_2_025C0B12 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_02CE0B11 |
1_2_02CE0B11 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_02CE2321 |
1_2_02CE2321 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_02CE9048 |
1_2_02CE9048 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_02CEF1E8 |
1_2_02CEF1E8 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_02CE9918 |
1_2_02CE9918 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_02CEDF49 |
1_2_02CEDF49 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_02CE8D00 |
1_2_02CE8D00 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_0641C33A |
1_2_0641C33A |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_06412D18 |
1_2_06412D18 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_06410830 |
1_2_06410830 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_06411FC8 |
1_2_06411FC8 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_0641CDA7 |
1_2_0641CDA7 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_065EF670 |
1_2_065EF670 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_065E56D8 |
1_2_065E56D8 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_065E8D38 |
1_2_065E8D38 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_065E6AA8 |
1_2_065E6AA8 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_065EB128 |
1_2_065EB128 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_065ECC20 |
1_2_065ECC20 |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Code function: 1_2_065EA060 |
1_2_065EA060 |
Source: sbuvJk8Zn8.exe, 00000000.00000000.1708723110.000000000043E000.00000002.00000001.01000000.00000003.sdmp |
Binary or memory string: OriginalFilenameXeno_manager.exe: vs sbuvJk8Zn8.exe |
Source: sbuvJk8Zn8.exe, 00000000.00000002.1711909983.00000000008DE000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameclr.dllT vs sbuvJk8Zn8.exe |
Source: sbuvJk8Zn8.exe, 00000001.00000002.4158499318.00000000010EE000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameclr.dllT vs sbuvJk8Zn8.exe |
Source: sbuvJk8Zn8.exe, 00000001.00000002.4163755149.0000000007818000.00000004.00000010.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameUNKNOWN_FILET vs sbuvJk8Zn8.exe |
Source: sbuvJk8Zn8.exe, 00000001.00000002.4162856979.0000000007220000.00000004.08000000.00040000.00000000.sdmp |
Binary or memory string: OriginalFilenameBouncyCastle.Crypto.dllP vs sbuvJk8Zn8.exe |
Source: sbuvJk8Zn8.exe, 00000001.00000002.4160898372.0000000005780000.00000004.08000000.00040000.00000000.sdmp |
Binary or memory string: OriginalFilenameKeyLoggerOffline.dllB vs sbuvJk8Zn8.exe |
Source: sbuvJk8Zn8.exe |
Binary or memory string: OriginalFilenameXeno_manager.exe: vs sbuvJk8Zn8.exe |
Source: sbuvJk8Zn8.exe.0.dr |
Binary or memory string: OriginalFilenameXeno_manager.exe: vs sbuvJk8Zn8.exe |
Source: 1.2.sbuvJk8Zn8.exe.62f0000.1.raw.unpack, type: UNPACKEDPE |
Matched rule: Quasar_RAT_1 date = 2017-04-07, hash4 = f08db220df716de3d4f63f3007a03f902601b9b32099d6a882da87312f263f34, hash3 = 515c1a68995557035af11d818192f7866ef6a2018aa13112fefbe08395732e89, hash2 = 1ce40a89ef9d56fd32c00db729beecc17d54f4f7c27ff22f708a957cd3f9a4ec, hash1 = 0774d25e33ca2b1e2ee2fafe3fdbebecefbf1d4dd99e6460f0bc8713dd0fd740, author = Florian Roth, description = Detects Quasar RAT, reference = https://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-annex-b-final.pdf, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 00000001.00000002.4161603732.00000000062F0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY |
Matched rule: Quasar_RAT_1 date = 2017-04-07, hash4 = f08db220df716de3d4f63f3007a03f902601b9b32099d6a882da87312f263f34, hash3 = 515c1a68995557035af11d818192f7866ef6a2018aa13112fefbe08395732e89, hash2 = 1ce40a89ef9d56fd32c00db729beecc17d54f4f7c27ff22f708a957cd3f9a4ec, hash1 = 0774d25e33ca2b1e2ee2fafe3fdbebecefbf1d4dd99e6460f0bc8713dd0fd740, author = Florian Roth, description = Detects Quasar RAT, reference = https://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-annex-b-final.pdf, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: sbuvJk8Zn8.exe, 00000001.00000002.4159148683.0000000003116000.00000004.00000800.00020000.00000000.sdmp, sbuvJk8Zn8.exe, 00000001.00000002.4159148683.0000000003067000.00000004.00000800.00020000.00000000.sdmp, sbuvJk8Zn8.exe, 00000001.00000002.4159148683.00000000030AE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Program Manager |
Source: sbuvJk8Zn8.exe, 00000001.00000002.4159148683.0000000003116000.00000004.00000800.00020000.00000000.sdmp, sbuvJk8Zn8.exe, 00000001.00000002.4159148683.0000000003067000.00000004.00000800.00020000.00000000.sdmp, sbuvJk8Zn8.exe, 00000001.00000002.4159148683.0000000003059000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: explorer - Prog@\^q explorer - Program Manager |
Source: sbuvJk8Zn8.exe, 00000001.00000002.4159148683.0000000003067000.00000004.00000800.00020000.00000000.sdmp, sbuvJk8Zn8.exe, 00000001.00000002.4159148683.00000000030AE000.00000004.00000800.00020000.00000000.sdmp, sbuvJk8Zn8.exe, 00000001.00000002.4159148683.0000000003262000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Program Managerx& |
Source: sbuvJk8Zn8.exe, 00000001.00000002.4159148683.0000000003116000.00000004.00000800.00020000.00000000.sdmp, sbuvJk8Zn8.exe, 00000001.00000002.4159148683.0000000003067000.00000004.00000800.00020000.00000000.sdmp, sbuvJk8Zn8.exe, 00000001.00000002.4159148683.0000000003059000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: explorer - Program Manager |
Source: sbuvJk8Zn8.exe, 00000001.00000002.4159148683.0000000003116000.00000004.00000800.00020000.00000000.sdmp, sbuvJk8Zn8.exe, 00000001.00000002.4159148683.0000000003067000.00000004.00000800.00020000.00000000.sdmp, sbuvJk8Zn8.exe, 00000001.00000002.4159148683.00000000030AE000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Program ManagerlB^q |
Source: sbuvJk8Zn8.exe, 00000001.00000002.4159148683.0000000002F40000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Program Manager@ |
Source: C:\Users\user\Desktop\sbuvJk8Zn8.exe |
Queries volume information: C:\Users\user\Desktop\sbuvJk8Zn8.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Queries volume information: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\sbuvJk8Zn8.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |