Source: C:\Users\user\Desktop\5daucomrx8.exe |
Code function: 0_2_004062D5 FindFirstFileW,FindClose, |
0_2_004062D5 |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Code function: 0_2_00402E18 FindFirstFileW, |
0_2_00402E18 |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Code function: 0_2_00406C9B DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, |
0_2_00406C9B |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_003547B7 GetFileAttributesW,FindFirstFileW,FindClose, |
17_2_003547B7 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_00353E72 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
17_2_00353E72 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0035C16C FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
17_2_0035C16C |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0035CB81 FindFirstFileW,FindClose, |
17_2_0035CB81 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0035CC0C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
17_2_0035CC0C |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0035F445 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
17_2_0035F445 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0035F5A2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
17_2_0035F5A2 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0035F8A3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
17_2_0035F8A3 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_00353B4F FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
17_2_00353B4F |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B0C16C FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
21_2_00B0C16C |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B047B7 GetFileAttributesW,FindFirstFileW,FindClose, |
21_2_00B047B7 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B0CB81 FindFirstFileW,FindClose, |
21_2_00B0CB81 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B0CC0C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
21_2_00B0CC0C |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B0F445 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
21_2_00B0F445 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B0F5A2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
21_2_00B0F5A2 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B0F8A3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
21_2_00B0F8A3 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B03B4F FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
21_2_00B03B4F |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B03E72 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
21_2_00B03E72 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00FC2022 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,___std_fs_open_handle@16,GetFileInformationByHandleEx,GetLastError,GetFileInformationByHandleEx,GetFileInformationByHandleEx, |
21_2_00FC2022 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_01056000 CreateDirectoryA,FindFirstFileA,FindNextFileA,GetLastError,FindClose, |
21_2_01056000 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_01076770 FindFirstFileA,SetFileAttributesA,DeleteFileA,FindNextFileA,FindClose,GetLastError,SetFileAttributesA,GetLastError,RemoveDirectoryA,GetLastError,GetLastError,std::_Throw_Cpp_error,std::_Throw_Cpp_error,CreateDirectoryA,std::_Throw_Cpp_error,std::_Throw_Cpp_error, |
21_2_01076770 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_010238D0 FindFirstFileA,FindNextFileA,GetLastError,FindClose, |
21_2_010238D0 |
Source: 5daucomrx8.exe, 00000000.00000003.1530090678.00000000028F0000.00000004.00000020.00020000.00000000.sdmp, Origin.pif, 0000000B.00000003.1605691240.00000000047B9000.00000004.00000800.00020000.00000000.sdmp, Origin.pif, 00000015.00000002.3984435194.0000000004E7D000.00000004.00000020.00020000.00000000.sdmp, Origin.pif.2.dr, SecureHawk.pif.11.dr, Beginning.0.dr |
String found in binary or memory: http://crl.globalsign.com/gs/gscodesigng2.crl0 |
Source: 5daucomrx8.exe, 00000000.00000003.1530090678.00000000028F0000.00000004.00000020.00020000.00000000.sdmp, Origin.pif, 0000000B.00000003.1605691240.00000000047B9000.00000004.00000800.00020000.00000000.sdmp, Origin.pif, 00000015.00000002.3984435194.0000000004E7D000.00000004.00000020.00020000.00000000.sdmp, Origin.pif.2.dr, SecureHawk.pif.11.dr, Beginning.0.dr |
String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingg2.crl0T |
Source: 5daucomrx8.exe, 00000000.00000003.1530090678.00000000028F0000.00000004.00000020.00020000.00000000.sdmp, Origin.pif, 0000000B.00000003.1605691240.00000000047B9000.00000004.00000800.00020000.00000000.sdmp, Origin.pif, 00000015.00000002.3984435194.0000000004E7D000.00000004.00000020.00020000.00000000.sdmp, Origin.pif.2.dr, SecureHawk.pif.11.dr, Beginning.0.dr |
String found in binary or memory: http://crl.globalsign.net/root.crl0 |
Source: 5daucomrx8.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: 5daucomrx8.exe, 00000000.00000003.1530090678.00000000028F0000.00000004.00000020.00020000.00000000.sdmp, Origin.pif, 0000000B.00000003.1605691240.00000000047B9000.00000004.00000800.00020000.00000000.sdmp, Origin.pif, 00000015.00000002.3984435194.0000000004E7D000.00000004.00000020.00020000.00000000.sdmp, Origin.pif.2.dr, SecureHawk.pif.11.dr, Beginning.0.dr |
String found in binary or memory: http://ocsp2.globalsign.com/gscodesigng20 |
Source: Origin.pif, 00000015.00000002.3983887690.000000000129E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://secure.globalsign.com/cacert/gscodesign0 |
Source: 5daucomrx8.exe, 00000000.00000003.1530090678.00000000028F0000.00000004.00000020.00020000.00000000.sdmp, Origin.pif, 0000000B.00000003.1605691240.00000000047B9000.00000004.00000800.00020000.00000000.sdmp, Origin.pif, 00000015.00000002.3984435194.0000000004E7D000.00000004.00000020.00020000.00000000.sdmp, Origin.pif.2.dr, SecureHawk.pif.11.dr, Beginning.0.dr |
String found in binary or memory: http://secure.globalsign.com/cacert/gscodesigng2.crt04 |
Source: 5daucomrx8.exe, 00000000.00000003.1530090678.00000000028F0000.00000004.00000020.00020000.00000000.sdmp, Origin.pif, 0000000B.00000003.1605691240.00000000047B9000.00000004.00000800.00020000.00000000.sdmp, Origin.pif, 00000015.00000002.3984435194.0000000004E7D000.00000004.00000020.00020000.00000000.sdmp, Origin.pif.2.dr, SecureHawk.pif.11.dr, Beginning.0.dr |
String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingg2.crt0 |
Source: 5daucomrx8.exe, 00000000.00000003.1530090678.00000000028F0000.00000004.00000020.00020000.00000000.sdmp, Origin.pif, 0000000B.00000003.1605691240.00000000047B9000.00000004.00000800.00020000.00000000.sdmp, Origin.pif, 00000015.00000002.3984435194.0000000004E7D000.00000004.00000020.00020000.00000000.sdmp, Origin.pif.2.dr, SecureHawk.pif.11.dr, Beginning.0.dr |
String found in binary or memory: http://www.autoitscript.com/autoit3/0 |
Source: 5daucomrx8.exe, 00000000.00000003.1560779161.0000000002900000.00000004.00000020.00020000.00000000.sdmp, Origin.pif, 0000000B.00000003.1605691240.00000000047B9000.00000004.00000800.00020000.00000000.sdmp, Origin.pif, 0000000B.00000000.1595592768.0000000000B68000.00000002.00000001.01000000.00000005.sdmp, SecureHawk.pif, 00000011.00000002.3983285511.00000000003B8000.00000002.00000001.01000000.00000008.sdmp, Origin.pif, 00000015.00000002.3983571280.0000000000B68000.00000002.00000001.01000000.00000005.sdmp, Origin.pif, 00000015.00000002.3984435194.0000000004E7D000.00000004.00000020.00020000.00000000.sdmp, Origin.pif.2.dr, Studios.0.dr, SecureHawk.pif.11.dr |
String found in binary or memory: http://www.autoitscript.com/autoit3/J |
Source: Origin.pif, Origin.pif, 00000015.00000002.3983668133.0000000000F90000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: http://www.winimage.com/zLibDll |
Source: Origin.pif |
String found in binary or memory: https://ipinfo.io/ |
Source: Origin.pif, 00000015.00000002.3983668133.0000000000F90000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io/https://www.maxmind.com/en/locate-my-ip-addressWs2_32.dll |
Source: Origin.pif, 00000015.00000002.3983887690.0000000001257000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://t.me/RiseProSUPPORT |
Source: 5daucomrx8.exe, 00000000.00000003.1530090678.00000000028F0000.00000004.00000020.00020000.00000000.sdmp, Origin.pif, 0000000B.00000003.1605691240.00000000047B9000.00000004.00000800.00020000.00000000.sdmp, Origin.pif, 00000015.00000002.3984435194.0000000004E7D000.00000004.00000020.00020000.00000000.sdmp, Origin.pif, 00000015.00000002.3983887690.000000000129E000.00000004.00000020.00020000.00000000.sdmp, Origin.pif.2.dr, SecureHawk.pif.11.dr, Beginning.0.dr |
String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: 5daucomrx8.exe, 00000000.00000003.1530090678.00000000028F0000.00000004.00000020.00020000.00000000.sdmp, Origin.pif, 0000000B.00000003.1605691240.00000000047B9000.00000004.00000800.00020000.00000000.sdmp, Origin.pif, 00000015.00000002.3984435194.0000000004E7D000.00000004.00000020.00020000.00000000.sdmp, Origin.pif.2.dr, SecureHawk.pif.11.dr, Beginning.0.dr |
String found in binary or memory: https://www.globalsign.com/repository/03 |
Source: Origin.pif, 00000015.00000002.3983887690.000000000129E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.globalsign.com/x |
Source: Origin.pif |
String found in binary or memory: https://www.maxmind.com/en/locate-my-ip-address |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0037CEDF DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, |
17_2_0037CEDF |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B2CEDF DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, |
21_2_00B2CEDF |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
File created: C:\Users\user\AppData\Local\Temp\Fighting entropy: 7.99892313786 |
Jump to dropped file |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
File created: C:\Users\user\AppData\Local\Temp\June entropy: 7.99829631291 |
Jump to dropped file |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
File created: C:\Users\user\AppData\Local\Temp\Massachusetts entropy: 7.99846554018 |
Jump to dropped file |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
File created: C:\Users\user\AppData\Local\Temp\Radius entropy: 7.99902505433 |
Jump to dropped file |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
File created: C:\Users\user\AppData\Local\Temp\Stockings entropy: 7.99820786051 |
Jump to dropped file |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
File created: C:\Users\user\AppData\Local\Temp\Bdsm entropy: 7.99861815368 |
Jump to dropped file |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
File created: C:\Users\user\AppData\Local\Temp\Vendor entropy: 7.99556101212 |
Jump to dropped file |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
File created: C:\Users\user\AppData\Local\Temp\Convenience entropy: 7.99573659303 |
Jump to dropped file |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
File created: C:\Users\user\AppData\Local\Temp\Joke entropy: 7.99883402213 |
Jump to dropped file |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
File created: C:\Users\user\AppData\Local\Temp\Severe entropy: 7.99824795157 |
Jump to dropped file |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
File created: C:\Users\user\AppData\Local\Temp\Falls entropy: 7.99917331785 |
Jump to dropped file |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
File created: C:\Users\user\AppData\Local\Temp\Sig entropy: 7.9984885368 |
Jump to dropped file |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
File created: C:\Users\user\AppData\Local\Temp\Outreach entropy: 7.99921983985 |
Jump to dropped file |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
File created: C:\Users\user\AppData\Local\Temp\Dental entropy: 7.99901607447 |
Jump to dropped file |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
File created: C:\Users\user\AppData\Local\Temp\Mask entropy: 7.99382891469 |
Jump to dropped file |
Source: C:\Windows\SysWOW64\cmd.exe |
File created: C:\Users\user\AppData\Local\Temp\369580\Z entropy: 7.99991695551 |
Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
File created: C:\Users\user\AppData\Local\LinkGuard Dynamics\r entropy: 7.99991695551 |
Jump to dropped file |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Code function: 0_2_0040497C |
0_2_0040497C |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Code function: 0_2_00406ED2 |
0_2_00406ED2 |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Code function: 0_2_004074BB |
0_2_004074BB |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_002FB020 |
17_2_002FB020 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_002F94E0 |
17_2_002F94E0 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_002F9C80 |
17_2_002F9C80 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_003781C8 |
17_2_003781C8 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_00312325 |
17_2_00312325 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_00326432 |
17_2_00326432 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0032258E |
17_2_0032258E |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_002FE6F0 |
17_2_002FE6F0 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0031275A |
17_2_0031275A |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_00370802 |
17_2_00370802 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_003288EF |
17_2_003288EF |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_003269A4 |
17_2_003269A4 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_00300A51 |
17_2_00300A51 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0034EB95 |
17_2_0034EB95 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_00300BE0 |
17_2_00300BE0 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_00370C7F |
17_2_00370C7F |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_00358CB1 |
17_2_00358CB1 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0031CC81 |
17_2_0031CC81 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_00326F16 |
17_2_00326F16 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_002F32EB |
17_2_002F32EB |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_003132E9 |
17_2_003132E9 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0031F339 |
17_2_0031F339 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0030D457 |
17_2_0030D457 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0030F57E |
17_2_0030F57E |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_003115E4 |
17_2_003115E4 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_002F1663 |
17_2_002F1663 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_002FF6A0 |
17_2_002FF6A0 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_003177F3 |
17_2_003177F3 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0031DAD5 |
17_2_0031DAD5 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_00311AD8 |
17_2_00311AD8 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_00329C15 |
17_2_00329C15 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0030DD14 |
17_2_0030DD14 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_00311EF0 |
17_2_00311EF0 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0031BF06 |
17_2_0031BF06 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B281C8 |
21_2_00B281C8 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AC2325 |
21_2_00AC2325 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AD6432 |
21_2_00AD6432 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AD258E |
21_2_00AD258E |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AAE6F0 |
21_2_00AAE6F0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AC275A |
21_2_00AC275A |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AD88EF |
21_2_00AD88EF |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B20802 |
21_2_00B20802 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AD69A4 |
21_2_00AD69A4 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AFEB95 |
21_2_00AFEB95 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AB0BE0 |
21_2_00AB0BE0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B08CB1 |
21_2_00B08CB1 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00ACCC81 |
21_2_00ACCC81 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B20C7F |
21_2_00B20C7F |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AD6F16 |
21_2_00AD6F16 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AAB020 |
21_2_00AAB020 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AC32E9 |
21_2_00AC32E9 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00ACF339 |
21_2_00ACF339 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AA94E0 |
21_2_00AA94E0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00ABD457 |
21_2_00ABD457 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AC15E4 |
21_2_00AC15E4 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00ABF57E |
21_2_00ABF57E |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AAF6A0 |
21_2_00AAF6A0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AA1663 |
21_2_00AA1663 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AC77F3 |
21_2_00AC77F3 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AC1AD8 |
21_2_00AC1AD8 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00ACDAD5 |
21_2_00ACDAD5 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AA9C80 |
21_2_00AA9C80 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AD9C15 |
21_2_00AD9C15 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00ABDD14 |
21_2_00ABDD14 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AC1EF0 |
21_2_00AC1EF0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00ACBF06 |
21_2_00ACBF06 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_01074BD0 |
21_2_01074BD0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_01098120 |
21_2_01098120 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_0107E170 |
21_2_0107E170 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_010931A0 |
21_2_010931A0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00FD002D |
21_2_00FD002D |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00FC71A0 |
21_2_00FC71A0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_01023080 |
21_2_01023080 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_010B20D0 |
21_2_010B20D0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_010860E0 |
21_2_010860E0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_01034320 |
21_2_01034320 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00F9A2C0 |
21_2_00F9A2C0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_010A2260 |
21_2_010A2260 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00FD036F |
21_2_00FD036F |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_0109A2B0 |
21_2_0109A2B0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_010A4550 |
21_2_010A4550 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_010CF550 |
21_2_010CF550 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_0101F590 |
21_2_0101F590 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_010885F0 |
21_2_010885F0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_01020440 |
21_2_01020440 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_01080450 |
21_2_01080450 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00FBF580 |
21_2_00FBF580 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_0108A480 |
21_2_0108A480 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_01087730 |
21_2_01087730 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_010D7760 |
21_2_010D7760 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_010C97B0 |
21_2_010C97B0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_010777E0 |
21_2_010777E0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00FE2610 |
21_2_00FE2610 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_01033610 |
21_2_01033610 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00FE47BF |
21_2_00FE47BF |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_010D86C0 |
21_2_010D86C0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_0108A930 |
21_2_0108A930 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_01087960 |
21_2_01087960 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_010D6970 |
21_2_010D6970 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_0107F9A0 |
21_2_0107F9A0 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_01082820 |
21_2_01082820 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00FCC960 |
21_2_00FCC960 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00FCA928 |
21_2_00FCA928 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_01088B40 |
21_2_01088B40 |
Source: unknown |
Process created: C:\Users\user\Desktop\5daucomrx8.exe "C:\Users\user\Desktop\5daucomrx8.exe" |
|
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /k copy Emotions Emotions.cmd & Emotions.cmd & exit |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa.exe opssvc.exe" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "avastui.exe avgui.exe bdservicehost.exe nswscsvc.exe sophoshealth.exe" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 369580 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "MaskBathroomsCompoundInjection" Participants |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b Massachusetts + Radius + Dental + Vendor + Fighting + June + Stockings + Convenience + Falls + Joke + Mask + Severe + Outreach + Sig + Bdsm 369580\Z |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\Temp\369580\Origin.pif 369580\Origin.pif 369580\Z |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\timeout.exe timeout 15 |
|
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Process created: C:\Windows\SysWOW64\schtasks.exe schtasks.exe /create /tn "SecureHawk" /tr "wscript //B 'C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.js'" /sc onlogon /F /RL HIGHEST |
|
Source: C:\Windows\SysWOW64\schtasks.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: unknown |
Process created: C:\Windows\System32\wscript.exe C:\Windows\system32\wscript.EXE //B "C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.js" |
|
Source: C:\Windows\System32\wscript.exe |
Process created: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif "C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif" "C:\Users\user\AppData\Local\LinkGuard Dynamics\r" |
|
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Process created: C:\Users\user\AppData\Local\Temp\369580\Origin.pif C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
|
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /k copy Emotions Emotions.cmd & Emotions.cmd & exit |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa.exe opssvc.exe" |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "avastui.exe avgui.exe bdservicehost.exe nswscsvc.exe sophoshealth.exe" |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 369580 |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "MaskBathroomsCompoundInjection" Participants |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b Massachusetts + Radius + Dental + Vendor + Fighting + June + Stockings + Convenience + Falls + Joke + Mask + Severe + Outreach + Sig + Bdsm 369580\Z |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\Temp\369580\Origin.pif 369580\Origin.pif 369580\Z |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\timeout.exe timeout 15 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Process created: C:\Windows\SysWOW64\schtasks.exe schtasks.exe /create /tn "SecureHawk" /tr "wscript //B 'C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.js'" /sc onlogon /F /RL HIGHEST |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Process created: C:\Users\user\AppData\Local\Temp\369580\Origin.pif C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process created: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif "C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif" "C:\Users\user\AppData\Local\LinkGuard Dynamics\r" |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: taskschd.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: xmllite.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: jscript.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: rstrtmgr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: d3d11.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: dxgi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: resourcepolicyclient.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: d3d10warp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: dxcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: gpedit.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: activeds.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: dssec.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: dsuiext.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: adsldpc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: dsrole.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: logoncli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: ntdsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: authz.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Section loaded: devobj.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0037577B IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, |
17_2_0037577B |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_00305EDA GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, |
17_2_00305EDA |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B2577B IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, |
21_2_00B2577B |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00AB5EDA GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, |
21_2_00AB5EDA |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Code function: 0_2_004062D5 FindFirstFileW,FindClose, |
0_2_004062D5 |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Code function: 0_2_00402E18 FindFirstFileW, |
0_2_00402E18 |
Source: C:\Users\user\Desktop\5daucomrx8.exe |
Code function: 0_2_00406C9B DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, |
0_2_00406C9B |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_003547B7 GetFileAttributesW,FindFirstFileW,FindClose, |
17_2_003547B7 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_00353E72 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
17_2_00353E72 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0035C16C FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
17_2_0035C16C |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0035CB81 FindFirstFileW,FindClose, |
17_2_0035CB81 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0035CC0C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
17_2_0035CC0C |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0035F445 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
17_2_0035F445 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0035F5A2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
17_2_0035F5A2 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_0035F8A3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
17_2_0035F8A3 |
Source: C:\Users\user\AppData\Local\LinkGuard Dynamics\SecureHawk.pif |
Code function: 17_2_00353B4F FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
17_2_00353B4F |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B0C16C FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
21_2_00B0C16C |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B047B7 GetFileAttributesW,FindFirstFileW,FindClose, |
21_2_00B047B7 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B0CB81 FindFirstFileW,FindClose, |
21_2_00B0CB81 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B0CC0C FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
21_2_00B0CC0C |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B0F445 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
21_2_00B0F445 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B0F5A2 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
21_2_00B0F5A2 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B0F8A3 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
21_2_00B0F8A3 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B03B4F FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
21_2_00B03B4F |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00B03E72 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
21_2_00B03E72 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_00FC2022 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,___std_fs_open_handle@16,GetFileInformationByHandleEx,GetLastError,GetFileInformationByHandleEx,GetFileInformationByHandleEx, |
21_2_00FC2022 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_01056000 CreateDirectoryA,FindFirstFileA,FindNextFileA,GetLastError,FindClose, |
21_2_01056000 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_01076770 FindFirstFileA,SetFileAttributesA,DeleteFileA,FindNextFileA,FindClose,GetLastError,SetFileAttributesA,GetLastError,RemoveDirectoryA,GetLastError,GetLastError,std::_Throw_Cpp_error,std::_Throw_Cpp_error,CreateDirectoryA,std::_Throw_Cpp_error,std::_Throw_Cpp_error, |
21_2_01076770 |
Source: C:\Users\user\AppData\Local\Temp\369580\Origin.pif |
Code function: 21_2_010238D0 FindFirstFileA,FindNextFileA,GetLastError,FindClose, |
21_2_010238D0 |