Source: 00000001.00000002.1820464419.0000000000400000.00000040.00000400.00020000.00000000.sdmp |
String decryptor: reinforcenh.shop |
Source: 00000001.00000002.1820464419.0000000000400000.00000040.00000400.00020000.00000000.sdmp |
String decryptor: stogeneratmns.shop |
Source: 00000001.00000002.1820464419.0000000000400000.00000040.00000400.00020000.00000000.sdmp |
String decryptor: fragnantbui.shop |
Source: 00000001.00000002.1820464419.0000000000400000.00000040.00000400.00020000.00000000.sdmp |
String decryptor: drawzhotdog.shop |
Source: 00000001.00000002.1820464419.0000000000400000.00000040.00000400.00020000.00000000.sdmp |
String decryptor: vozmeatillu.shop |
Source: 00000001.00000002.1820464419.0000000000400000.00000040.00000400.00020000.00000000.sdmp |
String decryptor: offensivedzvju.shop |
Source: 00000001.00000002.1820464419.0000000000400000.00000040.00000400.00020000.00000000.sdmp |
String decryptor: ghostreedmnu.shop |
Source: 00000001.00000002.1820464419.0000000000400000.00000040.00000400.00020000.00000000.sdmp |
String decryptor: gutterydhowi.shop |
Source: 00000001.00000002.1820464419.0000000000400000.00000040.00000400.00020000.00000000.sdmp |
String decryptor: pianoswimen.shop |
Source: 00000001.00000002.1820464419.0000000000400000.00000040.00000400.00020000.00000000.sdmp |
String decryptor: lid=%s&j=%s&ver=4.0 |
Source: 00000001.00000002.1820464419.0000000000400000.00000040.00000400.00020000.00000000.sdmp |
String decryptor: TeslaBrowser/5.5 |
Source: 00000001.00000002.1820464419.0000000000400000.00000040.00000400.00020000.00000000.sdmp |
String decryptor: - Screen Resoluton: |
Source: 00000001.00000002.1820464419.0000000000400000.00000040.00000400.00020000.00000000.sdmp |
String decryptor: - Physical Installed Memory: |
Source: 00000001.00000002.1820464419.0000000000400000.00000040.00000400.00020000.00000000.sdmp |
String decryptor: Workgroup: - |
Source: 00000001.00000002.1820464419.0000000000400000.00000040.00000400.00020000.00000000.sdmp |
String decryptor: tLYMe5--2 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
1_2_0040D060 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
1_2_0040D060 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp+10h] |
1_2_0040F4B0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then movzx edx, byte ptr [ecx+eax] |
1_2_0040F4B0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
1_2_0040EC00 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then movzx edi, byte ptr [eax+esi] |
1_2_00407000 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then movzx ecx, word ptr [edi+eax] |
1_2_004490D0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov byte ptr [edi], al |
1_2_00432080 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then jmp edx |
1_2_0040915E |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then cmp dword ptr [esi+edx*8], CECD21FDh |
1_2_0042C170 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then cmp dword ptr [edi+edx*8], CECD21FDh |
1_2_0042C170 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then add ebp, dword ptr [esp+0Ch] |
1_2_00431110 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov word ptr [edx], ax |
1_2_00429251 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
1_2_004452C0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then cmp dword ptr [esi+edx*8], 0633C81Dh |
1_2_004452C0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then movzx ebx, byte ptr [eax+edx] |
1_2_004452C0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
1_2_004452C0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esi+7Ch] |
1_2_00433FB3 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esi+7Ch] |
1_2_00433FB3 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, ecx |
1_2_004012BF |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-14h] |
1_2_0042E3C2 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp+0Ch] |
1_2_0044B3C0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then cmp dword ptr [ebx+edx*8], 7E28BDA7h |
1_2_0044B3C0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
1_2_004443D4 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then cmp byte ptr [esi+01h], 00000000h |
1_2_0041445A |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
1_2_0044440C |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then movzx eax, word ptr [esi+ecx] |
1_2_00442420 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp+0Ch] |
1_2_0044B550 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then cmp dword ptr [ebx+edx*8], 7E28BDA7h |
1_2_0044B550 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esi+7Ch] |
1_2_004335DA |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then jmp eax |
1_2_0042F64F |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then cmp word ptr [ecx+edx+02h], 0000h |
1_2_0044B6D0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then cmp dword ptr [ebp+edx*8+00h], 81105F7Ah |
1_2_0044B6D0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov ebx, dword ptr [edi+04h] |
1_2_00430740 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
1_2_00444740 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov word ptr [eax], cx |
1_2_00428710 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov dword ptr [esp], 00000000h |
1_2_0041A780 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov word ptr [eax], dx |
1_2_00420780 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov word ptr [eax], dx |
1_2_00420832 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then cmp dword ptr [edi+edx*8], 0633C81Dh |
1_2_00449950 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then jmp ecx |
1_2_0044A996 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
1_2_00427ADF |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov byte ptr [edi], al |
1_2_00432AB3 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov byte ptr [edi], al |
1_2_00432AB3 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then cmp byte ptr [esi+01h], 00000000h |
1_2_00413B52 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esi+20h] |
1_2_0040FB7C |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then movzx edx, byte ptr [esi+edi] |
1_2_00404B00 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then movzx ebx, byte ptr [edx] |
1_2_0043BBD0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then cmp dword ptr [ebx+edx*8], 1B788DCFh |
1_2_00444B80 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then movzx edx, byte ptr [esi+ebx] |
1_2_00405B90 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp+38h] |
1_2_00410BAE |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then cmp byte ptr [esi+eax], 00000000h |
1_2_00430C40 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then dec ebx |
1_2_0043FC70 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then cmp dword ptr [esi+edx*8], 0633C81Dh |
1_2_00445CE0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then cmp word ptr [ebp+edi+02h], 0000h |
1_2_00426C80 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov word ptr [eax], cx |
1_2_00426C80 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then add esi, 02h |
1_2_00413D32 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
1_2_0044BDC0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
1_2_00428DF0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp+00000660h] |
1_2_0041DE74 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp+00000660h] |
1_2_0041DE06 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then cmp dword ptr [esi+edx*8], 77DD2217h |
1_2_0041DE06 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then cmp dword ptr [edi+edx*8], 54CA534Eh |
1_2_00448ED0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov word ptr [eax], cx |
1_2_00426EF0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esp+34h] |
1_2_00445F60 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esi+7Ch] |
1_2_00433FB3 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 4x nop then mov eax, dword ptr [esi+7Ch] |
1_2_00433FB3 |
Source: file.exe |
String found in binary or memory: https://github.com/golang/protobuf/issues/1609): |
Source: BitLockerToGo.exe, 00000001.00000003.1808487829.0000000002C82000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://gutterydhowi.shop/ |
Source: BitLockerToGo.exe, 00000001.00000002.1820785163.0000000002C82000.00000004.00000020.00020000.00000000.sdmp, BitLockerToGo.exe, 00000001.00000003.1808487829.0000000002C6D000.00000004.00000020.00020000.00000000.sdmp, BitLockerToGo.exe, 00000001.00000002.1820785163.0000000002CA0000.00000004.00000020.00020000.00000000.sdmp, BitLockerToGo.exe, 00000001.00000003.1808657646.0000000002C84000.00000004.00000020.00020000.00000000.sdmp, BitLockerToGo.exe, 00000001.00000003.1808487829.0000000002C82000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://gutterydhowi.shop/api |
Source: BitLockerToGo.exe, 00000001.00000002.1820785163.0000000002C5C000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://gutterydhowi.shop/apiC |
Source: BitLockerToGo.exe, 00000001.00000002.1820785163.0000000002C82000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://gutterydhowi.shop/apisw |
Source: BitLockerToGo.exe, 00000001.00000002.1820785163.0000000002C5C000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://gutterydhowi.shop/api~ |
Source: BitLockerToGo.exe, 00000001.00000002.1820785163.0000000002C5C000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://gutterydhowi.shop/g |
Source: file.exe |
String found in binary or memory: https://management.azure.compending |
Source: BitLockerToGo.exe, 00000001.00000002.1820785163.0000000002C5C000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.cloudflare.com/5xx-err |
Source: BitLockerToGo.exe, 00000001.00000003.1808467665.0000000002CE7000.00000004.00000020.00020000.00000000.sdmp, BitLockerToGo.exe, 00000001.00000003.1808487829.0000000002C6D000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.cloudflare.com/5xx-error-landing |
Source: BitLockerToGo.exe, 00000001.00000003.1808467665.0000000002CE7000.00000004.00000020.00020000.00000000.sdmp, BitLockerToGo.exe, 00000001.00000003.1808487829.0000000002C6D000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.cloudflare.com/learning/access-management/phishing-attack/ |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_004403D0 |
1_2_004403D0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00447A52 |
1_2_00447A52 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00401000 |
1_2_00401000 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00437020 |
1_2_00437020 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0040915E |
1_2_0040915E |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0044A130 |
1_2_0044A130 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0044A19B |
1_2_0044A19B |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00429251 |
1_2_00429251 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_004052C0 |
1_2_004052C0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_004452C0 |
1_2_004452C0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00449FC0 |
1_2_00449FC0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0040B2E0 |
1_2_0040B2E0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0042D2E2 |
1_2_0042D2E2 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0040A2F0 |
1_2_0040A2F0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0040E290 |
1_2_0040E290 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_004012BF |
1_2_004012BF |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00407340 |
1_2_00407340 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0040136B |
1_2_0040136B |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0044A320 |
1_2_0044A320 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0041445A |
1_2_0041445A |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0043F4C0 |
1_2_0043F4C0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00449480 |
1_2_00449480 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0042D578 |
1_2_0042D578 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_004155DC |
1_2_004155DC |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_004405A4 |
1_2_004405A4 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_004405A4 |
1_2_004405A4 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0040166E |
1_2_0040166E |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00423672 |
1_2_00423672 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_004036F0 |
1_2_004036F0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0042B810 |
1_2_0042B810 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00449950 |
1_2_00449950 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0044A9A2 |
1_2_0044A9A2 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00438A50 |
1_2_00438A50 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00427ADF |
1_2_00427ADF |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0044BAF0 |
1_2_0044BAF0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00413B52 |
1_2_00413B52 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0042DB06 |
1_2_0042DB06 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00433B19 |
1_2_00433B19 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00410BAE |
1_2_00410BAE |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00407D40 |
1_2_00407D40 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00409D09 |
1_2_00409D09 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0040BDF0 |
1_2_0040BDF0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00436DB0 |
1_2_00436DB0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0040AE50 |
1_2_0040AE50 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_0041DE06 |
1_2_0041DE06 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00449FC0 |
1_2_00449FC0 |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Code function: 1_2_00410FD0 |
1_2_00410FD0 |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: powrprof.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: umpdc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: webio.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: file.exe, 00000000.00000002.1802808473.0000000002002000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: reinforcenh.shop |
Source: file.exe, 00000000.00000002.1802808473.0000000002002000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: stogeneratmns.shop |
Source: file.exe, 00000000.00000002.1802808473.0000000002002000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: fragnantbui.shop |
Source: file.exe, 00000000.00000002.1802808473.0000000002002000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: drawzhotdog.shop |
Source: file.exe, 00000000.00000002.1802808473.0000000002002000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: vozmeatillu.shop |
Source: file.exe, 00000000.00000002.1802808473.0000000002002000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: offensivedzvju.shop |
Source: file.exe, 00000000.00000002.1802808473.0000000002002000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: ghostreedmnu.shop |
Source: file.exe, 00000000.00000002.1802808473.0000000002002000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: gutterydhowi.shop |
Source: file.exe, 00000000.00000002.1802808473.0000000002002000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: pianoswimen.shop |