Source: Harbor Freight Department.png |
Virustotal: Detection: 17% |
Perma Link |
Source: C:\Windows\SysWOW64\mspaint.exe |
Memory allocated: 770B0000 page execute and read and write |
Jump to behavior |
Source: classification engine |
Classification label: mal48.winPNG@1/0@0/0 |
Source: C:\Windows\SysWOW64\mspaint.exe |
Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Jump to behavior |
Source: Harbor Freight Department.png |
Virustotal: Detection: 17% |
Source: C:\Windows\SysWOW64\mspaint.exe |
Section loaded: wow64win.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Section loaded: wow64cpu.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Section loaded: mfc42u.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Section loaded: odbc32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Section loaded: msftedit.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Section loaded: rpcrtremote.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Section loaded: wiatrace.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Section loaded: uiribbonres.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Section loaded: bcrypt.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
File opened: C:\Windows\SysWOW64\MSFTEDIT.DLL |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe TID: 3484 |
Thread sleep time: -240000s >= -30000s |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Queries volume information: C:\Users\user\Desktop\Harbor Freight Department.png VolumeInformation |
Jump to behavior |