Windows Analysis Report
mal2

Overview

General Information

Sample name: mal2
Analysis ID: 1523388
MD5: 5daadb531113cad75786097b02e393f0
SHA1: 9dfad0a4084103d1fb53a9e2f7637a5ba7667ceb
SHA256: f57bc4c23407f071076c629e9ca80dd737d034dafc216595b5fba3e29d4b2c1b
Infos:

Detection

Score: 72
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus detection for dropped file
Multi AV Scanner detection for submitted file
Creates files in the recycle bin to hide itself
Drops PE files to the startup folder
Drops or copies MsMpEng.exe (Windows Defender, likely to bypass HIPS)
Machine Learning detection for dropped file
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
Sigma detected: Startup Folder File Write
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

AV Detection

barindex
Source: C:\ProgramData\Microsoft\Diagnosis\osver.txt.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\_curlrc.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\MF\Active.GRL.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\Users\Public\Desktop\Adobe Acrobat.lnk.exe.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\Users\Public\Desktop\Google Chrome.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\MF\Pending.GRL.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\.curlrc.exe.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\.curlrc.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\Users\Public\Desktop\Adobe Acrobat.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Diagnosis\parse.dat.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: mal2 ReversingLabs: Detection: 95%
Source: C:\ProgramData\Microsoft\Diagnosis\osver.txt.tmp Joe Sandbox ML: detected
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Joe Sandbox ML: detected
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk.tmp Joe Sandbox ML: detected
Source: C:\ProgramData\_curlrc.tmp Joe Sandbox ML: detected
Source: C:\ProgramData\Microsoft\MF\Active.GRL.tmp Joe Sandbox ML: detected
Source: C:\Users\Public\Desktop\Adobe Acrobat.lnk.exe.tmp Joe Sandbox ML: detected
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk.tmp Joe Sandbox ML: detected
Source: C:\Users\Public\Desktop\Google Chrome.lnk.tmp Joe Sandbox ML: detected
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Joe Sandbox ML: detected
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk.tmp Joe Sandbox ML: detected
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Joe Sandbox ML: detected
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk.tmp Joe Sandbox ML: detected
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Joe Sandbox ML: detected
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk.tmp Joe Sandbox ML: detected
Source: C:\ProgramData\Microsoft\MF\Pending.GRL.tmp Joe Sandbox ML: detected
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Joe Sandbox ML: detected
Source: C:\ProgramData\.curlrc.exe.tmp Joe Sandbox ML: detected
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk.tmp Joe Sandbox ML: detected
Source: C:\ProgramData\.curlrc.tmp Joe Sandbox ML: detected
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Joe Sandbox ML: detected
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Joe Sandbox ML: detected
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Joe Sandbox ML: detected
Source: C:\Users\Public\Desktop\Adobe Acrobat.lnk.tmp Joe Sandbox ML: detected
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Joe Sandbox ML: detected
Source: C:\ProgramData\Microsoft\Diagnosis\parse.dat.tmp Joe Sandbox ML: detected
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk.tmp Joe Sandbox ML: detected
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Joe Sandbox ML: detected
Source: mal2 Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Users\user\Desktop\mal2.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\.curlrc.exe
Source: C:\Users\user\Desktop\mal2.exe File opened: C:\Documents and Settings\All Users\Application Data\.curlrc.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\.curlrc.exe
Source: C:\Users\user\Desktop\mal2.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\.curlrc.exe
Source: C:\Users\user\Desktop\mal2.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\.curlrc.exe
Source: C:\Users\user\Desktop\mal2.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\.curlrc.exe
Source: mal2 Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engine Classification label: mal72.adwa.evad.win@1/1025@0/0
Source: C:\Users\user\Desktop\mal2.exe File read: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini
Source: C:\Users\user\Desktop\mal2.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: mal2 ReversingLabs: Detection: 95%
Source: C:\Users\user\Desktop\mal2.exe File read: C:\Users\user\Desktop\mal2.exe
Source: C:\Users\user\Desktop\mal2.exe Section loaded: apphelp.dll
Source: C:\Users\user\Desktop\mal2.exe Section loaded: mfc42.dll
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.Onboarding.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpasdlta.lkg.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpavdlta.lkg.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-48.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.PhoneLink.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e64ffef1-e246-b632-595b-56076a3fa776.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\gl-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nl-NL\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\Browse Extras.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Run Script (x86).lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpClient.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\ASAP_CloudPolicy.json.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fr-FR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Buffers.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\el-GR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mi-NZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2010Win64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Users\Public\Documents\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fr-CA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\LfSvc\Geofence\GeofenceApplicationID.dat.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpSenseComm.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlp.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Office365Win64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\ecbc2601-0a67-4963-e594-43c65d6ec9a5.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Rest.ClientRuntime.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.provider.e_sqlite3.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\DesktopSettings2013.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Newtonsoft.Json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ko-KR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\6e90ed81-9187-fa62-ce90-f18d7bed6b12.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\_curlrc.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftLync2013Win64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.Bluetooth.Pal.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Drivers\WdDevFlt.sys.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\el-GR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\gu-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\.curlrc.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.app.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\a7e08b8b-ad4b-af00-ebcc-1aa29a833ce9.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.lib.e_sqlite3.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\Scripts\RegisterInboxTemplates.ps1.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP,0.23082.41.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Users\Public\Documents\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Polly.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b34b197c-c0ed-bf12-c9bb-44e883c66a9d.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Drivers\WdBoot.sys.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Users\Public\Desktop\Adobe Acrobat.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\bcda97bb-bfd0-2a72-3c90-c8518f3d09ee.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b59f5123-f94a-28bc-cf2d-1f77c3cd60ad.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-GB\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-MX\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Windows.AugLoop.Core.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\state.rsm.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpAzSubmit.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpAsDesc.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jtx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\en-GB\confident.cov.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,System.Management.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\it-IT\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nl-NL\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fi-FI\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mr-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\el-GR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\ea39969e-9808-10a2-23ff-be783a132fea.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user.dat.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fr-CA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-ES\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\he-IL\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\StorageGroveler.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\eee47229-947d-2ac7-e8a3-49bafee251d1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDetours.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\lv-LV\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Transport,0.7.2012.2221.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\865e8f30-20a1-9528-bb48-42999b5b2aa8.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\f1d940d0-b5b2-0083-8403-807a8db430d5.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-US\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\TroubleshootingSvc.json.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Xaml.Behaviors.Wpf,1.1.39.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\kn-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpUpdate.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,System.IdentityModel.Tokens.Jwt.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\he-IL\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlpCmd.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.Obex,0.23051.1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\da-DK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\de-DE\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\Templates\SettingsLocationTemplate.xsd.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\eu-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftLync2010.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2013CAWin64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\DefenderCSP.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\kok-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.Onboarding,0.23082.41.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\MF\Active.GRL.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Xaml.Behaviors.Wpf.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\hardz.dat.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\config.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\lv-LV\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Win64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\it-IT\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb00012.jtx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftLync2013Win32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.bundle_e_sqlite3.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\is-IS\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDetoursCopyAccelerator.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\CortanaUWP.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mpextms.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\SmsRouter\MessageStore\SmsInterceptStore.jfm.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpasdlta.vdm.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-192.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.PlatformSdk.Protocol.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Rest.ClientRuntime,2.3.24.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nl-NL\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Users\Public\Pictures\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Common,0.7.2012.2221.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\Templates\SettingsLocationTemplate2013.xsd.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,System.IO.Abstractions.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.bundle_e_sqlite3,2.1.4.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\guest.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Common.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e8ac9388-7c9c-19cc-fd4d-cb72bb1544ea.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x64).lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\osver.txt.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\9a9f1e94-851b-c6b4-27c0-55a242e0d96d.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\TightVNC\tvnserver.log.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.Common.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\Defender.psd1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nb-NO\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Drivers\WdNisDrv.sys.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.jfm.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpSvc.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Users\Public\Desktop\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Users\Public\Desktop\Google Chrome.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pl-PL\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.SideChannel.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\DirectXDbVersion.json.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.core.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpRtp.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-32.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Codecs.Protobuf.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\a1e5b165-0532-a6a3-f542-0c5c162be3e1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\abbb44f6-ae33-2e7c-ac40-4d8ac17bf46b.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpEvMsg.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.url.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\71c8f37a-a7b9-aff0-6de0-9b276c089ad6.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\EventStore.db.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Win32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.Auth,0.23082.41.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpUpdate.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\kk-KZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.lib.e_sqlite3,2.1.4.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpSvc.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Unknown.Log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e9bff135-4a26-0e2f-d743-30d9666eed8e.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Users\Public\Music\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Polly.Extensions.Http.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MPDetection-20231003-085557.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Caches\cversions.2.db.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nb-NO\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpRtp.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Drivers\WdFilter.sys.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\id-ID\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,System.IO.Abstractions,19.2.51.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\endpointdlp.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\71ef3df1-f4b1-69cd-793a-48e165e282aa.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8ce3d3dd-a4c7-6c38-5fde-1f9f5df98807.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hr-HR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json.bk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\lt-LT\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Users\Public\Desktop\Firefox.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\ETLLogs\ShutdownLogger\Diagtrack-Listener.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftWordpad.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\AutoItX\AutoItX Help File.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\IdentityCRL\INT\wlidsvcconfig.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Users\Public\Desktop\Google Chrome.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\cb692946-a9f3-639d-1064-a6d75a01b9c3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\RecoveryDrive.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8292682a-6850-c06c-9b6d-9646f16d4ed0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fil-PH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\de-DE\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b81d7e70-84e7-b16a-e3d0-1e7aa2f1232d.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-20231003-085557.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013BackupWin64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hr-HR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\LfSvc\Geofence\GeofenceApplicationID.dat.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.Bluetooth.Pbap.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbres00002.jrs.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\AutoIt v3 Website.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrc.idx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpScan.cdxml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip Help.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nb-NO\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Users\Public\Videos\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,HtmlAgilityPack.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Users\Public\Desktop\Firefox.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpavdlta.vdm.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft OneDrive\setup\refcount.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user.bmp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.ServicesClient.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\AppV\Setup\OfficeIntegrator.ps1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\ThemeSettings2013.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\NetworkPrinters.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-40.png.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\832f9d1e-5f47-dfb1-157b-5239adf4c1db.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b6126597-8ecb-81b4-8b3a-1430dc2988c1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hi-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.lkg.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-48.png.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.core,2.1.4.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpOAV.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\tokens.dat.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\SCCInstallService.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Network\Downloader\edbres00002.jrs.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\fc93b452-8a84-dede-3b7a-0fc9413c4592.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.PlatformSdk,0.23082.41.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\d834be1c-66d4-85d2-5bfc-720e73e8e544.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-40.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\ac116a72-b6b1-d558-23f6-10796e634d41.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Examples.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e2a686b1-b02a-b3e7-90cb-3fa0d708ce04.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\UsoSettings.json.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Office\ClickToRunPackageLocker.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Google.Protobuf.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\SmsRouter\MessageStore\SmsInterceptStore.db.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\MpDiag.bin.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.YourPhone.Vcard.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Stateless.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\en-GB\fyi.cov.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\CortanaUWP.json.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Quick Assist.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftInternetExplorer2013.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.Common,0.23082.41.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.SideChannel.Protocol.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Polly,7.2.4.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ko-KR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-32.png.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\MpDiag.bin.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mk-MK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\AppxProvisioning.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\7309084a-bb6f-20c3-ea54-aa108ceab1ae.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.url.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbres00001.jrs.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpEvMsg.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\7646fa0f-b52c-71a8-3aed-950dd1668c09.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-US\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,TestableIO.System.IO.Abstractions.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\ca947da2-7e9a-7249-8095-bceb379c6f74.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,System.IO.Pipelines.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft OneDrive\setup\refcount.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\EaseOfAccessSettings2013.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016Win32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013BackupWin32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpLics.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\km-KH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpOAV.dll.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ko-KR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8d56e57b-8663-136d-ff69-a004e217825a.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\id-ID\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.Auth.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\TroubleshootingSvc.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ga-IE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\IdentityCRL\production\wlidsvcconfig.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-ES\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\c3d42a1a-2f3f-a4a9-6a04-cc1b234485fb.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\it-IT\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Network\Downloader\edb.log.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hu-HU\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mpextms.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.IdentityModel.Tokens.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\6ffa25dc-c89d-3de9-3601-df09bae65a75.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\d1ecfce2-f845-c1e9-052b-d2f457c135e6.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Codecs.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\en-GB\urgent.cov.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\en-GB\WelcomeFax.tif.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\StorageGroveler.json.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\RoamingCredentialSettings.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e8fff2df-6041-8f21-3df7-db31661aa09b.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCommu.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\f5fc8c03-78f6-342c-372b-15d02609bd3c.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Codecs,0.7.2012.2221.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Network\Downloader\edb00001.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016BackupWin32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.url.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Examples.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hu-HU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCommu.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\TenantStorage\P-ARIA\EventStore.db.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fr-FR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\a92561ce-87c0-7d40-42ea-c87d237c0db0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Users\Public\Videos\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\parse.dat.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e78cdb72-8076-1aa5-5df6-048300a0f594.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.Diagnostics.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.Bluetooth.Map.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip Help.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.privacy.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\c94a6c18-d496-da1c-8a02-fc6976e0145e.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Network\Downloader\edbtmp.log.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\et-EE\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\History.Log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Buffers,0.7.2012.2221.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpClient.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ml-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mt-MT\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.url.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8cfc804a-d777-2361-1670-4569e516397e.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\bbfbe8ad-1a35-a7f3-33bc-40912bf89dfb.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Toolkit.Uwp.Notifications.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb00014.jtx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\bb26a0e5-d235-0ee6-0c36-6d5e185fa5b1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2013CAWin32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpLics.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\lb-LU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\AppV\Setup\OfficeIntegrator.ps1.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\9d3ad23c-c6b8-7fb5-e4ab-f5d0a66dcfbc.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.WindowsAppSDK.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\91a5b4c7-29a8-ec80-4321-fbecea906705.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\ScenariosSqlStore\EventStore.db.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.Obex.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.PlatformSdk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Help File.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Stateless,5.13.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\en-GB\generic.cov.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Network\Downloader\edb.chk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Windows.Apps.TraceLogging.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\wfp\wfpdiag.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\CTAC.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Polly.Extensions.Http,3.0.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ms-MY\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jcp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\DirectXDbVersion.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpAsDesc.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.app.json.bk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\de-DE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb00013.jtx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Run Script (x64).lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016Win64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\da-DK\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.PhoneLink,0.23082.41.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Registry Editor.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ja-JP\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\Policy.vpol.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-192.png.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\jones.dat.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fr-FR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\MF\Pending.GRL.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftNotepad.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-US\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.NET.StringTools.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.NET.StringTools,17.4.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016BackupWin64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\SCCInstallService.json.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Users\Public\Music\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Users\Public\Desktop\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hu-HU\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Microsoft-Antimalware-RTP.man.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\6ab96728-2783-240f-370f-afa9d4e52fdd.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-MX\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ka-GE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\VdiState.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ja-JP\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbtmp.jtx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\FeatureConfig.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Network\Downloader\edbres00001.jrs.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8e383e90-b2f9-7bf2-1d5b-4e47dcb2014e.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,MessagePack.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.allow.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x86).lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.cert.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\lt-LT\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpUxAgent.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\da-DK\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,System.IO.Pipelines,7.0.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ne-NP\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Transport.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,System.Management,7.0.1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Detections.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\ASAP_CloudPolicy.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ja-JP\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Office365Win32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\osver.txt.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\gd-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\Templates\SettingsLocationTemplate2013A.xsd.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Newtonsoft.Json,10.0.3.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.SideChannel,0.23082.41.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fi-FI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fi-FI\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftInternetExplorer2013.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\.curlrc.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fa-IR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2010Win32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\UsoSettings.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Users\Public\Desktop\Adobe Acrobat.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\lo-LA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Users\Public\Pictures\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\et-EE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Microsoft-Antimalware-NIS.man.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\folder.ico.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\te-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpasdlta.lkg.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpavdlta.lkg.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpClient.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.PhoneLink.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Google.Protobuf,3.23.4.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.IdentityModel.Abstractions.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Caching.Abstractions,7.0.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\gl-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sr-Cyrl-RS\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpClient.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Skype for Business Recording Manager.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\en-GB\mpasdesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\el-GR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Buffers.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2010Win64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ja-JP\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftSkypeForBusiness2016Win32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpAsDesc.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ko-KR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpSenseComm.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,MessagePack.Annotations,2.6.100-alpha.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlp.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Office365Win64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.provider.e_sqlite3.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\DesktopSettings2013.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\6e90ed81-9187-fa62-ce90-f18d7bed6b12.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hu-HU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\1faf63f7-f387-4522-1175-68c9652d968a.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\306e67c8-9a1d-38de-8654-054bd8a6e6d6.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\AutoItX\AutoItX Help File.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Drivers\WdDevFlt.sys.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\el-GR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\.curlrc.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\a7e08b8b-ad4b-af00-ebcc-1aa29a833ce9.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.lib.e_sqlite3.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\Scripts\RegisterInboxTemplates.ps1.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin64.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fi-FI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\Defender.psd1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.IdentityModel.JsonWebTokens.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b34b197c-c0ed-bf12-c9bb-44e883c66a9d.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\52a7e8cc-4b89-0eb8-5b4c-0f924bfc3949.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-GB\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Windows.AugLoop.Core.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\state.rsm.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpAzSubmit.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\ReportLatency\Latency\19\0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jtx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpAsDesc.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,TestableIO.System.IO.Abstractions,19.2.51.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\1f7b7aa2-506a-03cd-6648-5b78ac12040f.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\el-GR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user.dat.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Office Language Preferences.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\ReportLatency\Latency\01\2.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\StorageGroveler.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDetours.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Transport,0.7.2012.2221.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\154E23D0-C644-4E6F-8CE6-5069272F999F.vsch.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\865e8f30-20a1-9528-bb48-42999b5b2aa8.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\f1d940d0-b5b2-0083-8403-807a8db430d5.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-US\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\TroubleshootingSvc.json.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Xaml.Behaviors.Wpf,1.1.39.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\kn-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.PlatformSdk.Protocol,0.23082.41.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,System.IdentityModel.Tokens.Jwt.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_pref.ico.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\he-IL\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.Obex,0.23051.1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\da-DK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\C773B593-9C79-47E6-BF01-073C12072B16\x-none.16\i320.c2rx.hash.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sk-SK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ug-CN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpAsDesc.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ar-SA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Windows.AugLoop.Core,0.0.230717008.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\215f9712-9fca-a3f8-5b11-660eefc73b96.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2013CAWin64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.outlookmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\config.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\hardz.dat.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hr-HR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Win64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.dcfmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftLync2013Win32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\93BCA88018E5993458BC6BBE55D33E61.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDetoursCopyAccelerator.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\CortanaUWP.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.fbe50464-f61d-4a15-a5b7-ed239a079807.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MPDetection-20231003-085557.log.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Spreadsheet Compare.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-CN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-192.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.PlatformSdk.Protocol.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Rest.ClientRuntime,2.3.24.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpClient.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\de-DE\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.0884f9b2-b6ec-4b87-899f-510361add0dc.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nl-NL\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\ReportLatency\Latency\19\1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.AspNetCore.SignalR.Client.Core,7.0.9.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.AspNetCore.SignalR.Client.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\0f8e2cd5-b8eb-7a22-b9e9-9b1183fa0a84.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\el-GR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mk-MK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.bundle_e_sqlite3,2.1.4.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e8ac9388-7c9c-19cc-fd4d-cb72bb1544ea.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x64).lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\osver.txt.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-Eco3PTelDefault.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\da-DK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pl-PL\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sr-Latn-RS\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.f4d4c9b8-57b5-43ca-ab7a-5d857e7666b9.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin32.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.cert.json.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.jfm.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\kn-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pl-PL\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Data.Sqlite.Core.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.SideChannel.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.core.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ug-CN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\SciTE Script Editor.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpRtp.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fr-FR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\km-KH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-32.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Codecs.Protobuf.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.AspNetCore.SignalR.Common,7.0.9.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\a1e5b165-0532-a6a3-f542-0c5c162be3e1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Antimalware-NIS.man.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ga-IE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\abbb44f6-ae33-2e7c-ac40-4d8ac17bf46b.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Primitives.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.url.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Graphics.Win2D.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\netfol.ico.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\kk-KZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.IdentityModel.Abstractions,6.32.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Unknown.Log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\cy-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e9bff135-4a26-0e2f-d743-30d9666eed8e.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\sr-Latn-RS\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ja-JP\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MPDetection-20231003-085557.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ar-SA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Caches\cversions.2.db.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpRtp.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\3f446420-d8ef-3b9c-d5b4-ba09c43121b4.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\et-EE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\cs-CZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,System.IO.Abstractions,19.2.51.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Spreadsheet Compare.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Logging,7.0.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\cs-CZ\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\vi-VN\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\th-TH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpUxAgent.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\state.rsm.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpAzSubmit.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\zh-CN\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hr-HR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json.bk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\bg-BG\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\gl-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Http.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\AutoItX\AutoItX Help File.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\RecoveryDrive.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8292682a-6850-c06c-9b6d-9646f16d4ed0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\endpointdlp.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.2.Crwl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fil-PH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\de-DE\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013BackupWin64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hr-HR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\61b5bd89-4cb0-db77-6622-cb63b5a58080.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.YourPhone.LibNanoApi.Managed.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbres00002.jrs.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\af-ZA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftInternetExplorer2013Backup.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\AutoIt v3 Website.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpDetours.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\lb-LU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\vi-VN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrc.idx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpScan.cdxml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nb-NO\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,HtmlAgilityPack.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ru-RU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\C73297F3A28B41D0B045DECE1D0D81EF.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.DependencyInjection.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sk-SK\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft OneDrive\setup\refcount.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\AppV\Setup\OfficeIntegrator.ps1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\USOShared\Logs\User\UpdateUx.475a5b13-420d-4358-9fdb-c77913ec90af.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\ThemeSettings2013.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.officemui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Options.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b6126597-8ecb-81b4-8b3a-1430dc2988c1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\lv-LV\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hu-HU\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\de-DE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\az-Latn-AZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpOAV.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Network\Downloader\edbres00002.jrs.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\Browse Extras.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\fc93b452-8a84-dede-3b7a-0fc9413c4592.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftLync2013Win64.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftSkypeForBusiness2016Win32.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\sr-Cyrl-RS\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-40.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Office\ClickToRunPackageLocker.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Google.Protobuf.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\0a8c1492-65ca-6a01-de25-0e183559d10d.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Catalogs\IGD.CAT.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\SmsRouter\MessageStore\SmsInterceptStore.db.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\MpDiag.bin.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.YourPhone.Vcard.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\cs-CZ\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.480bc3f4-4991-4ffc-b70d-c15db82e9d6a.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\81FE2459AB45799D6C1FB53DEEE30AF6.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Stateless.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\az-Latn-AZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmuxmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Quick Assist.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftInternetExplorer2013.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MsMpLics.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fr-FR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.Common,0.23082.41.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Logging.Abstractions.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Polly,7.2.4.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\uk-UA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\zh-CN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\tt-RU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ko-KR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pt-PT\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ko-KR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Logging.Debug.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-32.png.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Unknown.Log.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Antimalware-RTP.man.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Drivers\WdBoot.sys.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fa-IR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\AppxProvisioning.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\7309084a-bb6f-20c3-ea54-aa108ceab1ae.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fr-CA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hi-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\zh-TW\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Database Compare.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbres00001.jrs.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpEvMsg.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\7646fa0f-b52c-71a8-3aed-950dd1668c09.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\th-TH\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.a686e598-6877-4264-9711-989651a302f7.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,System.IO.Pipelines.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\EaseOfAccessSettings2013.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\tr-TR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013BackupWin32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpLics.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\uk-UA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.1d47542d-bdee-4dc6-94ed-be9cdb6f14e1.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-MX\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\cs-CZ\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ta-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\km-KH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Logging.Abstractions,7.0.1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.3.gthr.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.wordmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ko-KR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Detections.log.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.f3f7cc8e-795b-4925-9b8c-26e2ea300f41.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8d56e57b-8663-136d-ff69-a004e217825a.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\sl-SI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.Auth.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\ringtones.ico.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-ES\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Features,7.0.9.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.Crwl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\C773B593-9C79-47E6-BF01-073C12072B16\en-us.16\s321033.hash.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ka-GE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Telemetry Log for Office.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\it-IT\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\en-US\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpCmdRun.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Network\Downloader\edb.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hu-HU\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ko-KR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\kk-KZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.IdentityModel.Tokens.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\gu-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\2ff6ba33-4212-e6d3-dcc2-11aadb3d61ef.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\da-DK\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pa-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\StorageGroveler.json.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\folder.ico.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\TELEMETRY.ASM-WINDOWSSQ.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ThirdPartyNotices.txt.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-MX\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hr-HR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\Policy.vpol_.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\f5fc8c03-78f6-342c-372b-15d02609bd3c.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Codecs,0.7.2012.2221.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pt-PT\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\de-DE\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016BackupWin32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Network\Downloader\edb00001.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Examples.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hu-HU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ur-PK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\cs-CZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fr-FR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\a92561ce-87c0-7d40-42ea-c87d237c0db0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\C773B593-9C79-47E6-BF01-073C12072B16\x-none.16\s320.hash.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\parse.dat.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e78cdb72-8076-1aa5-5df6-048300a0f594.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Check For SQLite Updates.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ta-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2013CAWin32.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.IdentityModel.JsonWebTokens,6.32.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\History.Log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\13edb933-4688-0f79-3d0a-499edf952ba0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpClient.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.AspNetCore.SignalR.Protocols.Json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sr-Latn-RS\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ml-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mt-MT\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sl-SI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpOAV.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\0f8e2cd5-b8eb-7a22-b9e9-9b1183fa0a84.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpScan.cdxml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\bbfbe8ad-1a35-a7f3-33bc-40912bf89dfb.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.a821f645-76e8-4ba9-965c-60ad931c30ce.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Graphics.Win2D,1.0.5.1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\1e225998-faa0-5fd4-4db7-5e7686ee3b47.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Drivers\WdNisDrv.sys.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.accessmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDetours.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ro-RO\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb00014.jtx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\vi-VN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpLics.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\9d3ad23c-c6b8-7fb5-e4ab-f5d0a66dcfbc.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.Bluetooth.Map,0.23051.1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.Obex.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Help File.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ur-PK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office64mui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\History.Log.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\SciTE Script Editor.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\en-GB\generic.cov.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\CTAC.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jcp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ru-RU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\sync.ico.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftLync2010.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.app.json.bk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ProtectionManagement.mof.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-ES\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\vi-VN\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\da-DK\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.AspNetCore.Http.Connections.Common.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ja-JP\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-192.png.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\AutoIt v3 Website.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\2b5d0f60-d93b-1629-f3e5-4167231c7ee6.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\MF\Pending.GRL.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftNotepad.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\en-GB\mpasdesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pt-PT\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.NET.StringTools,17.4.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Caching.Memory,7.0.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016BackupWin64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\el-GR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.provider.e_sqlite3,2.1.4.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\sq-AL\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hu-HU\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\ThemeSettings2013.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\6ab96728-2783-240f-370f-afa9d4e52fdd.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ka-GE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\VdiState.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\0890ad2f-b74f-c384-f684-9c33f8f67924.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbtmp.jtx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8e383e90-b2f9-7bf2-1d5b-4e47dcb2014e.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,MessagePack.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Http,7.0.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.IdentityModel.Logging,6.32.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pl-PL\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.cert.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\lt-LT\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\2F1A6504-0641-44CF-8BB5-3612D865F2E5.vsch.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Transport.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Detections.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\ASAP_CloudPolicy.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Office365Win32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\Templates\SettingsLocationTemplate2013A.xsd.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.SideChannel,0.23082.41.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fi-FI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\67447b0c-05cf-6740-5f7b-391ab440c42d.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.AspNetCore.SignalR.Common.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fa-IR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\.curlrc.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2010Win32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\lo-LA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.Onboarding.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\it-IT\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ru-RU\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-48.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e64ffef1-e246-b632-595b-56076a3fa776.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\C773B593-9C79-47E6-BF01-073C12072B16\operations.db.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nl-NL\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\Browse Extras.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Run Script (x86).lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ar-SA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\ASAP_CloudPolicy.json.exe.tmp Jump to dropped file

Boot Survival

barindex
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\desktop.ini.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Access.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\desktop.ini.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Excel.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Firefox.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\OneNote.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Outlook.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Word.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\desktop.ini.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\7-Zip\7-Zip Help.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Access.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessibility\desktop.ini.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\desktop.ini.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Notepad.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Paint.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Quick Assist.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Snipping Tool.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Wordpad.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Adobe Acrobat.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Examples.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\desktop.ini.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Excel.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Firefox Private Browsing.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Firefox.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Google Chrome.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Immersive Control Panel.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\About Java.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\Check For Updates.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\Configure Java.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\Get Help.url.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\Visit Java.com.url.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Maintenance\Desktop.ini.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Edge.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\OneNote.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Outlook.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\PowerPoint.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Publisher.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Skype for Business.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\StartUp\desktop.ini.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\System Tools\desktop.ini.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\System Tools\Task Manager.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Word.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip Help.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Accessories\desktop.ini.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Examples.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Java\Get Help.url.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.url.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Publisher.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\StartUp\desktop.ini.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\desktop.ini.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessibility\desktop.ini.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessibility\Speech Recognition.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Math Input Panel.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Quick Assist.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Snipping Tool.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Steps Recorder.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\System Tools\Character Map.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\System Tools\desktop.ini.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Windows Media Player.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Component Services.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Computer Management.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\desktop.ini.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\dfrgui.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Event Viewer.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Print Management.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\RecoveryDrive.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Registry Editor.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\System Configuration.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\System Information.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\AutoIt Help File.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x64).lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x86).lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Check For SQLite Updates.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Check For Updates.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Compile Script to .exe (x64).lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Compile Script to .exe (x86).lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Extras\AutoIt v3 Website.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Extras\AutoItX\AutoItX Help File.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Extras\Browse Extras.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Run Script (x64).lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Run Script (x86).lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\SciTE Script Editor.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Firefox Private Browsing.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Immersive Control Panel.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\Check For Updates.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office Tools\Database Compare.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office Tools\Spreadsheet Compare.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\System Tools\Task Manager.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Windows PowerShell\desktop.ini.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\desktop.ini.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\RecoveryDrive.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Registry Editor.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Help File.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x64).lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x86).lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Check For SQLite Updates.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Check For Updates.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\AutoIt v3 Website.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\Browse Extras.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Run Script (x64).lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Run Script (x86).lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\SciTE Script Editor.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\desktop.ini.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\System Tools\Character Map.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Component Services.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Computer Management.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\System Configuration.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\System Information.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Compile Script to .exe (x64).lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Compile Script to .exe (x86).lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Extras\AutoItX\AutoItX Help File.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Immersive Control Panel.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office Tools\Database Compare.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office Tools\Office Language Preferences.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office Tools\Skype for Business Recording Manager.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office Tools\Spreadsheet Compare.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office Tools\Telemetry Log for Office.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Office Language Preferences.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Telemetry Log for Office.lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Windows Defender Firewall with Advanced Security.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Immersive Control Panel.lnk.tmp
Source: C:\Users\user\Desktop\mal2.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office Tools\Skype for Business Recording Manager.lnk.exe.tmp

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Users\user\Desktop\mal2.exe File created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp
Source: C:\Users\user\Desktop\mal2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\mal2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\mal2.exe Window / User API: threadDelayed 735
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\folder.ico.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\te-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpasdlta.lkg.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpavdlta.lkg.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpClient.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.PhoneLink.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.IdentityModel.Abstractions.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Google.Protobuf,3.23.4.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Caching.Abstractions,7.0.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\gl-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\User Account Pictures\user.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sr-Cyrl-RS\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpClient.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Skype for Business Recording Manager.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\en-GB\mpasdesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Buffers.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\el-GR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2010Win64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ja-JP\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftSkypeForBusiness2016Win32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpAsDesc.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ko-KR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpSenseComm.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,MessagePack.Annotations,2.6.100-alpha.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Office365Win64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlp.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.provider.e_sqlite3.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\DesktopSettings2013.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\6e90ed81-9187-fa62-ce90-f18d7bed6b12.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hu-HU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\1faf63f7-f387-4522-1175-68c9652d968a.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\306e67c8-9a1d-38de-8654-054bd8a6e6d6.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\AutoItX\AutoItX Help File.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Drivers\WdDevFlt.sys.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\el-GR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\.curlrc.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\a7e08b8b-ad4b-af00-ebcc-1aa29a833ce9.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.lib.e_sqlite3.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\Scripts\RegisterInboxTemplates.ps1.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin64.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fi-FI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\Defender.psd1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.IdentityModel.JsonWebTokens.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b34b197c-c0ed-bf12-c9bb-44e883c66a9d.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\52a7e8cc-4b89-0eb8-5b4c-0f924bfc3949.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm.tmp
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-GB\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Windows.AugLoop.Core.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\state.rsm.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpAzSubmit.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\ReportLatency\Latency\19\0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jtx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpAsDesc.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,TestableIO.System.IO.Abstractions,19.2.51.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\1f7b7aa2-506a-03cd-6648-5b78ac12040f.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\el-GR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\User Account Pictures\user.dat.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Office Language Preferences.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\ReportLatency\Latency\01\2.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDetours.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\OneSettings\StorageGroveler.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Transport,0.7.2012.2221.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\154E23D0-C644-4E6F-8CE6-5069272F999F.vsch.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\865e8f30-20a1-9528-bb48-42999b5b2aa8.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\f1d940d0-b5b2-0083-8403-807a8db430d5.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-US\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\OneSettings\TroubleshootingSvc.json.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Xaml.Behaviors.Wpf,1.1.39.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\kn-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.PlatformSdk.Protocol,0.23082.41.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_pref.ico.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,System.IdentityModel.Tokens.Jwt.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\he-IL\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.Obex,0.23051.1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\da-DK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\C773B593-9C79-47E6-BF01-073C12072B16\x-none.16\i320.c2rx.hash.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sk-SK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpAsDesc.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ug-CN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ar-SA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Windows.AugLoop.Core,0.0.230717008.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\215f9712-9fca-a3f8-5b11-660eefc73b96.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2013CAWin64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.outlookmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\User Account Pictures\hardz.dat.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\OneSettings\config.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hr-HR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Win64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.dcfmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftLync2013Win32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\93BCA88018E5993458BC6BBE55D33E61.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDetoursCopyAccelerator.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\OneSettings\CortanaUWP.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\USOShared\Logs\User\NotifyIcon.fbe50464-f61d-4a15-a5b7-ed239a079807.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Spreadsheet Compare.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Support\MPDetection-20231003-085557.log.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-CN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\User Account Pictures\user-192.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.PlatformSdk.Protocol.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Rest.ClientRuntime,2.3.24.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpClient.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\de-DE\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\USOShared\Logs\User\NotifyIcon.0884f9b2-b6ec-4b87-899f-510361add0dc.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nl-NL\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\Users\Public\Pictures\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\ReportLatency\Latency\19\1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.AspNetCore.SignalR.Client.Core,7.0.9.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.AspNetCore.SignalR.Client.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\0f8e2cd5-b8eb-7a22-b9e9-9b1183fa0a84.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\el-GR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mk-MK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.bundle_e_sqlite3,2.1.4.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e8ac9388-7c9c-19cc-fd4d-cb72bb1544ea.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x64).lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Diagnosis\osver.txt.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-Eco3PTelDefault.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\da-DK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pl-PL\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sr-Latn-RS\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\USOShared\Logs\User\NotifyIcon.f4d4c9b8-57b5-43ca-ab7a-5d857e7666b9.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin32.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.cert.json.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.jfm.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\kn-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\Users\Public\Desktop\Google Chrome.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pl-PL\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Data.Sqlite.Core.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.SideChannel.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.core.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ug-CN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\SciTE Script Editor.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpRtp.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\km-KH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fr-FR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\User Account Pictures\user-32.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Codecs.Protobuf.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.AspNetCore.SignalR.Common,7.0.9.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\a1e5b165-0532-a6a3-f542-0c5c162be3e1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ga-IE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Antimalware-NIS.man.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\abbb44f6-ae33-2e7c-ac40-4d8ac17bf46b.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Primitives.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.url.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Graphics.Win2D.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\netfol.ico.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\kk-KZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.IdentityModel.Abstractions,6.32.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\cy-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e9bff135-4a26-0e2f-d743-30d9666eed8e.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\sr-Latn-RS\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ja-JP\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Support\MPDetection-20231003-085557.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ar-SA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Caches\cversions.2.db.tmp
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpRtp.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\3f446420-d8ef-3b9c-d5b4-ba09c43121b4.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\et-EE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\cs-CZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,System.IO.Abstractions,19.2.51.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Spreadsheet Compare.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Logging,7.0.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\cs-CZ\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\vi-VN\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\th-TH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\state.rsm.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpUxAgent.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpAzSubmit.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\zh-CN\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hr-HR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json.bk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\bg-BG\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\gl-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Http.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\AutoItX\AutoItX Help File.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\RecoveryDrive.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8292682a-6850-c06c-9b6d-9646f16d4ed0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\endpointdlp.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.2.Crwl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fil-PH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\de-DE\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013BackupWin64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hr-HR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\61b5bd89-4cb0-db77-6622-cb63b5a58080.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.YourPhone.LibNanoApi.Managed.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbres00002.jrs.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\af-ZA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftInternetExplorer2013Backup.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\AutoIt v3 Website.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpDetours.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\lb-LU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\vi-VN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrc.idx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpScan.cdxml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nb-NO\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\Users\Public\Videos\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,HtmlAgilityPack.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ru-RU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\Users\Public\Desktop\Firefox.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\C73297F3A28B41D0B045DECE1D0D81EF.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.DependencyInjection.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sk-SK\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft OneDrive\setup\refcount.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\AppV\Setup\OfficeIntegrator.ps1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\USOShared\Logs\User\UpdateUx.475a5b13-420d-4358-9fdb-c77913ec90af.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\ThemeSettings2013.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.officemui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Options.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b6126597-8ecb-81b4-8b3a-1430dc2988c1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\lv-LV\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hu-HU\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\de-DE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\az-Latn-AZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpOAV.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Network\Downloader\edbres00002.jrs.tmp
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\Browse Extras.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\fc93b452-8a84-dede-3b7a-0fc9413c4592.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftLync2013Win64.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftSkypeForBusiness2016Win32.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\sr-Cyrl-RS\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\User Account Pictures\user-40.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Office\ClickToRunPackageLocker.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Google.Protobuf.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\0a8c1492-65ca-6a01-de25-0e183559d10d.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Catalogs\IGD.CAT.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\SmsRouter\MessageStore\SmsInterceptStore.db.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\MpDiag.bin.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.YourPhone.Vcard.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\cs-CZ\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\USOShared\Logs\User\NotifyIcon.480bc3f4-4991-4ffc-b70d-c15db82e9d6a.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\81FE2459AB45799D6C1FB53DEEE30AF6.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Stateless.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\az-Latn-AZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmuxmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Quick Assist.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftInternetExplorer2013.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MsMpLics.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fr-FR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.Common,0.23082.41.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Logging.Abstractions.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Polly,7.2.4.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\uk-UA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\zh-CN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\tt-RU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pt-PT\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ko-KR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ko-KR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Logging.Debug.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\User Account Pictures\user-32.png.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Antimalware-RTP.man.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Drivers\WdBoot.sys.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fa-IR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\AppxProvisioning.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\7309084a-bb6f-20c3-ea54-aa108ceab1ae.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fr-CA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hi-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\zh-TW\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Database Compare.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbres00001.jrs.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpEvMsg.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\7646fa0f-b52c-71a8-3aed-950dd1668c09.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\th-TH\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\USOShared\Logs\User\NotifyIcon.a686e598-6877-4264-9711-989651a302f7.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,System.IO.Pipelines.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\EaseOfAccessSettings2013.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\tr-TR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013BackupWin32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpLics.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\uk-UA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\USOShared\Logs\User\NotifyIcon.1d47542d-bdee-4dc6-94ed-be9cdb6f14e1.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-MX\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\cs-CZ\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ta-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\km-KH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Logging.Abstractions,7.0.1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.3.gthr.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.wordmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ko-KR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Detections.log.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\USOShared\Logs\User\NotifyIcon.f3f7cc8e-795b-4925-9b8c-26e2ea300f41.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8d56e57b-8663-136d-ff69-a004e217825a.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\sl-SI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.Auth.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\ringtones.ico.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Features,7.0.9.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-ES\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.Crwl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\C773B593-9C79-47E6-BF01-073C12072B16\en-us.16\s321033.hash.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ka-GE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Telemetry Log for Office.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\it-IT\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\en-US\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpCmdRun.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Network\Downloader\edb.log.tmp
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hu-HU\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ko-KR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\kk-KZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.IdentityModel.Tokens.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\gu-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\2ff6ba33-4212-e6d3-dcc2-11aadb3d61ef.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\da-DK\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pa-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\OneSettings\StorageGroveler.json.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\folder.ico.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\TELEMETRY.ASM-WINDOWSSQ.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ThirdPartyNotices.txt.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-MX\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hr-HR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\Policy.vpol_.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\f5fc8c03-78f6-342c-372b-15d02609bd3c.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Codecs,0.7.2012.2221.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pt-PT\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\de-DE\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016BackupWin32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Network\Downloader\edb00001.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Examples.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hu-HU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ur-PK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\cs-CZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fr-FR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\a92561ce-87c0-7d40-42ea-c87d237c0db0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\C773B593-9C79-47E6-BF01-073C12072B16\x-none.16\s320.hash.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\Users\Public\Videos\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Diagnosis\parse.dat.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e78cdb72-8076-1aa5-5df6-048300a0f594.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Check For SQLite Updates.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ta-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2013CAWin32.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.IdentityModel.JsonWebTokens,6.32.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\13edb933-4688-0f79-3d0a-499edf952ba0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\History.Log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpClient.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.AspNetCore.SignalR.Protocols.Json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sr-Latn-RS\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ml-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mt-MT\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sl-SI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpOAV.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\0f8e2cd5-b8eb-7a22-b9e9-9b1183fa0a84.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpScan.cdxml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\bbfbe8ad-1a35-a7f3-33bc-40912bf89dfb.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\USOShared\Logs\User\NotifyIcon.a821f645-76e8-4ba9-965c-60ad931c30ce.1.etl.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Graphics.Win2D,1.0.5.1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\1e225998-faa0-5fd4-4db7-5e7686ee3b47.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Drivers\WdNisDrv.sys.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.accessmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ro-RO\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDetours.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb00014.jtx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\vi-VN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpLics.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\9d3ad23c-c6b8-7fb5-e4ab-f5d0a66dcfbc.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.Bluetooth.Map,0.23051.1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Internal.Obex.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Help File.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ur-PK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office64mui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\History.Log.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\SciTE Script Editor.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\en-GB\generic.cov.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\OneSettings\CTAC.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jcp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ru-RU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\sync.ico.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftLync2010.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.app.json.bk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ProtectionManagement.mof.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\vi-VN\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-ES\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\da-DK\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.AspNetCore.Http.Connections.Common.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ja-JP\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\User Account Pictures\user-192.png.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\AutoIt v3 Website.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\2b5d0f60-d93b-1629-f3e5-4167231c7ee6.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\MF\Pending.GRL.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftNotepad.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\en-GB\mpasdesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pt-PT\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.NET.StringTools,17.4.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Caching.Memory,7.0.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016BackupWin64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\el-GR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\Users\Public\Music\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SQLitePCLRaw.provider.e_sqlite3,2.1.4.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\sq-AL\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\Users\Public\Desktop\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hu-HU\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\ThemeSettings2013.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\6ab96728-2783-240f-370f-afa9d4e52fdd.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ka-GE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\VdiState.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\0890ad2f-b74f-c384-f684-9c33f8f67924.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbtmp.jtx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8e383e90-b2f9-7bf2-1d5b-4e47dcb2014e.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,MessagePack.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Extensions.Http,7.0.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.IdentityModel.Logging,6.32.0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pl-PL\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.cert.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\lt-LT\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\2F1A6504-0641-44CF-8BB5-3612D865F2E5.vsch.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,SpanNetty.Transport.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Detections.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\OneSettings\ASAP_CloudPolicy.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Office365Win32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\Templates\SettingsLocationTemplate2013A.xsd.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.SideChannel,0.23082.41.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fi-FI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.AspNetCore.SignalR.Common.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\67447b0c-05cf-6740-5f7b-391ab440c42d.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\.curlrc.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fa-IR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2010Win32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\Users\Public\Desktop\Adobe Acrobat.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\lo-LA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\Users\Public\Pictures\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,YourPhone.YPP.Onboarding.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\it-IT\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ru-RU\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\User Account Pictures\user-48.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e64ffef1-e246-b632-595b-56076a3fa776.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\C773B593-9C79-47E6-BF01-073C12072B16\operations.db.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nl-NL\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe TID: 784 Thread sleep count: 735 > 30
Source: C:\Users\user\Desktop\mal2.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\.curlrc.exe
Source: C:\Users\user\Desktop\mal2.exe File opened: C:\Documents and Settings\All Users\Application Data\.curlrc.exe.tmp
Source: C:\Users\user\Desktop\mal2.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\.curlrc.exe
Source: C:\Users\user\Desktop\mal2.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\.curlrc.exe
Source: C:\Users\user\Desktop\mal2.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\.curlrc.exe
Source: C:\Users\user\Desktop\mal2.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\.curlrc.exe

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\mal2.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe.tmp Jump to dropped file
⊘No contacted IP infos