Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_0012BA94 FindFirstFileW,FindFirstFileW,GetLastError,FindNextFileW,GetLastError, |
1_2_0012BA94 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_0013D410 SendDlgItemMessageW,EndDialog,GetDlgItem,SetFocus,SetDlgItemTextW,SendDlgItemMessageW,FindFirstFileW,_swprintf,SetDlgItemTextW,FindClose,_swprintf,SetDlgItemTextW,SendDlgItemMessageW,_swprintf,SetDlgItemTextW,_swprintf,SetDlgItemTextW, |
1_2_0013D410 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_0014C4F8 FindFirstFileExA, |
1_2_0014C4F8 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_00127AAF: __EH_prolog,_wcslen,_wcslen,CreateFileW,CloseHandle,CreateDirectoryW,CreateFileW,DeviceIoControl,CloseHandle,GetLastError,RemoveDirectoryW,DeleteFileW, |
1_2_00127AAF |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_001292C6 |
1_2_001292C6 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_00137DCC |
1_2_00137DCC |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_00135001 |
1_2_00135001 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_00138243 |
1_2_00138243 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_00135272 |
1_2_00135272 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_00146298 |
1_2_00146298 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_001302F7 |
1_2_001302F7 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_001313F6 |
1_2_001313F6 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_0013741E |
1_2_0013741E |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_001464C7 |
1_2_001464C7 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_001355A0 |
1_2_001355A0 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_0014E5F0 |
1_2_0014E5F0 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_001307A0 |
1_2_001307A0 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_0012D833 |
1_2_0012D833 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_0013889F |
1_2_0013889F |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_0012395A |
1_2_0012395A |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_0014EA9E |
1_2_0014EA9E |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_00124A8E |
1_2_00124A8E |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_00152BA4 |
1_2_00152BA4 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_0012FCCC |
1_2_0012FCCC |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_00122EB6 |
1_2_00122EB6 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: String function: 0013FEEC appears 42 times |
|
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: String function: 0013FFC0 appears 56 times |
|
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: String function: 00140790 appears 31 times |
|
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_0013B6C2 FindResourceW,SizeofResource,LoadResource,LockResource,GlobalAlloc,GlobalLock,CreateStreamOnHGlobal,GdipCreateHBITMAPFromBitmap,GlobalUnlock,GlobalFree, |
1_2_0013B6C2 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: <pi-ms-win-core-synch-l1-2-0.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: <pi-ms-win-core-fibers-l1-1-1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: <pi-ms-win-core-synch-l1-2-0.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: <pi-ms-win-core-fibers-l1-1-1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: <pi-ms-win-core-localization-l1-2-1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: dxgidebug.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: ieframe.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: netapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: wkscli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: dataexchange.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: d3d11.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: dcomp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: dxgi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: twinapi.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: msiso.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: mshtml.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: powrprof.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: umpdc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: srpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: msimtf.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: d2d1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: dwrite.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: resourcepolicyclient.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: d3d10warp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: dxcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: mlang.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: uiautomationcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: HSZXPMB7kS.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT |
Source: HSZXPMB7kS.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE |
Source: HSZXPMB7kS.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC |
Source: HSZXPMB7kS.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: HSZXPMB7kS.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG |
Source: HSZXPMB7kS.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT |
Source: HSZXPMB7kS.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: HSZXPMB7kS.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: HSZXPMB7kS.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: HSZXPMB7kS.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: HSZXPMB7kS.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_0012BA94 FindFirstFileW,FindFirstFileW,GetLastError,FindNextFileW,GetLastError, |
1_2_0012BA94 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_0013D410 SendDlgItemMessageW,EndDialog,GetDlgItem,SetFocus,SetDlgItemTextW,SendDlgItemMessageW,FindFirstFileW,_swprintf,SetDlgItemTextW,FindClose,_swprintf,SetDlgItemTextW,SendDlgItemMessageW,_swprintf,SetDlgItemTextW,_swprintf,SetDlgItemTextW, |
1_2_0013D410 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_0014C4F8 FindFirstFileExA, |
1_2_0014C4F8 |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_001409FA IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
1_2_001409FA |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_00140B8D SetUnhandledExceptionFilter, |
1_2_00140B8D |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_00140D7A SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
1_2_00140D7A |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_00144FDF IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
1_2_00144FDF |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Queries volume information: C:\Windows\Fonts\times.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HSZXPMB7kS.exe |
Code function: 1_2_0013F04C GetCommandLineW,OpenFileMappingW,MapViewOfFile,UnmapViewOfFile,CloseHandle,GetModuleFileNameW,SetEnvironmentVariableW,GetLocalTime,_swprintf,SetEnvironmentVariableW,GetModuleHandleW,LoadIconW,DialogBoxParamW,Sleep,DeleteObject,DeleteObject,CloseHandle, |
1_2_0013F04C |