Source: Yara match | File source: bWrRSlOThY.exe, type: SAMPLE |
Source: Yara match | File source: 0.0.bWrRSlOThY.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000000.00000002.2592455877.0000000000409000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: bWrRSlOThY.exe PID: 3884, type: MEMORYSTR |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Uninstall.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\cookie_exporter.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\aimgr.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\DATABASECOMPARE.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\joticon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\Wordconv.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoasb.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\accicons.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\svchost.com, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SkypeSrv\SKYPESERVER.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\WORDICON.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mpextms.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\identity_helper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSQRY32.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Source user\OSE.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\OLicenseHeartbeat.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrBroker.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\AppSharingHookController64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SELFCERT.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\SPREADSHEETCOMPARE.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_pwa_launcher.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\dbcicons.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.Loader.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SCANPST.EXE, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\BHO\ie_to_edge_stub.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ORGCHART.EXE, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\VPREVIEW.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\OcPubMgr.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe, type: DROPPED |
Source: Yara match | File source: C:\Users\user\AppData\Local\Temp\chrome.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\PPTICO.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\wordicon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\PerfBoost.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Aut2Exe\upx.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrSanBroker.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\officeappguardwin32.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOICONS.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Au3Info.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Au3Check.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\sscicons.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\140\SQLDumper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLED.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\notification_click_helper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\grv_icons.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\lyncicon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\FLTLDR.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_proxy.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\osmclienticon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\notification_helper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pptico.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\OLCFG.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pj11icon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\xlicons.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ACCICONS.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE, type: DROPPED |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\PerfBoost.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpCmdRun.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\MSOHTMED.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-006E-0409-0000-0000000FF1CE}\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-0C0A-0000-0000000FF1CE}\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_pwa_launcher.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\FLTLDR.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SELFCERT.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SCANPST.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\xlicons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCopyAccelerator.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_proxy.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\accicons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\lyncicon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Users\user\AppData\Local\Temp\chrome.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\notification_click_helper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\officeappguardwin32.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\wordicon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\SPREADSHEETCOMPARE.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ConfigSecurityPolicy.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pj11icon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ACCICONS.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\AppSharingHookController64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\elevation_service.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\joticon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SkypeSrv\SKYPESERVER.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\Install\{EB80938B-EC00-4683-A2CC-456206E3A4E1}\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mpextms.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge_pwa_launcher.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\cookie_exporter.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-0409-0000-0000000FF1CE}\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\BHO\ie_to_edge_stub.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pptico.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\dbcicons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSQRY32.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-040C-0000-0000000FF1CE}\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ORGCHART.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\PPTICO.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\osmclienticon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\WORDICON.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrSanBroker.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\upx.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\Uninstall.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\sscicons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpCmdRun.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\cookie_exporter.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\notification_helper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLED.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mpextms.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrBroker.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\Wordconv.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlpCmd.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\pwahelper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\OcPubMgr.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\aimgr.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.Loader.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\VPREVIEW.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\OLCFG.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\grv_icons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoasb.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\identity_helper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe | Jump to behavior |
Source: bWrRSlOThY.exe, type: SAMPLE | Matched rule: Detects Neshta Author: ditekSHen |
Source: dump.pcap, type: PCAP | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 18.2.RemoteDestopManagerx86.exe.2997de0.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 18.2.RemoteDestopManagerx86.exe.2997de0.0.unpack, type: UNPACKEDPE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 0.0.bWrRSlOThY.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Detects Neshta Author: ditekSHen |
Source: 29.2.RemoteDestopManagerx86.exe.2b37fac.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 29.2.RemoteDestopManagerx86.exe.2b37fac.1.unpack, type: UNPACKEDPE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 29.2.RemoteDestopManagerx86.exe.2b48848.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 29.2.RemoteDestopManagerx86.exe.2b48848.0.unpack, type: UNPACKEDPE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 2.2.bWrRSlOThY.exe.32c7dec.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 2.2.bWrRSlOThY.exe.32c7dec.1.unpack, type: UNPACKEDPE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 2.2.bWrRSlOThY.exe.32d867c.0.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 2.2.bWrRSlOThY.exe.32d867c.0.raw.unpack, type: UNPACKEDPE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 18.2.RemoteDestopManagerx86.exe.29a8670.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 18.2.RemoteDestopManagerx86.exe.29a8670.1.unpack, type: UNPACKEDPE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 19.2.RemoteDestopManagerx86.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 19.2.RemoteDestopManagerx86.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 2.2.bWrRSlOThY.exe.32d867c.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 2.2.bWrRSlOThY.exe.32d867c.0.unpack, type: UNPACKEDPE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 18.2.RemoteDestopManagerx86.exe.2997de0.0.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 18.2.RemoteDestopManagerx86.exe.2997de0.0.raw.unpack, type: UNPACKEDPE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 18.2.RemoteDestopManagerx86.exe.29a8670.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 18.2.RemoteDestopManagerx86.exe.29a8670.1.raw.unpack, type: UNPACKEDPE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 29.2.RemoteDestopManagerx86.exe.2b48848.0.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 29.2.RemoteDestopManagerx86.exe.2b48848.0.raw.unpack, type: UNPACKEDPE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 2.2.bWrRSlOThY.exe.32c7dec.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 2.2.bWrRSlOThY.exe.32c7dec.1.raw.unpack, type: UNPACKEDPE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 29.2.RemoteDestopManagerx86.exe.2b37fac.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 29.2.RemoteDestopManagerx86.exe.2b37fac.1.raw.unpack, type: UNPACKEDPE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 0000001E.00000002.3408804926.0000000004CC8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000003.00000002.4617709059.000000000120E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000013.00000002.2815936645.0000000004DF8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000013.00000002.2813685167.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 00000013.00000002.2813685167.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 00000002.00000002.2164810535.00000000032C2000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 00000002.00000002.2164810535.00000000032C2000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 00000030.00000002.4609082147.0000000000866000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000012.00000002.2769868231.0000000002992000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 00000012.00000002.2769868231.0000000002992000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 00000027.00000002.4004536747.0000000000FBA000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000003.00000002.4617709059.00000000011A8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 0000001D.00000002.3361345490.0000000002B32000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 0000001D.00000002.3361345490.0000000002B32000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 00000003.00000002.4619895119.0000000002D41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000030.00000002.4611188210.000000000272F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000027.00000002.4005507938.0000000002AFF000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 0000001E.00000002.3398649421.0000000002681000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000013.00000002.2814476665.00000000028E1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: Process Memory Space: bWrRSlOThY.exe PID: 5332, type: MEMORYSTR | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: Process Memory Space: bWrRSlOThY.exe PID: 5100, type: MEMORYSTR | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: Process Memory Space: RemoteDestopManagerx86.exe PID: 2308, type: MEMORYSTR | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: Process Memory Space: RemoteDestopManagerx86.exe PID: 5332, type: MEMORYSTR | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: Process Memory Space: RemoteDestopManagerx86.exe PID: 5332, type: MEMORYSTR | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: Process Memory Space: RemoteDestopManagerx86.exe PID: 340, type: MEMORYSTR | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: Process Memory Space: RemoteDestopManagerx86.exe PID: 6476, type: MEMORYSTR | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: Process Memory Space: RemoteDestopManagerx86.exe PID: 760, type: MEMORYSTR | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: Process Memory Space: RemoteDestopManagerx86.exe PID: 1524, type: MEMORYSTR | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\AutoIt3\Uninstall.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\cookie_exporter.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\aimgr.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\DATABASECOMPARE.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\joticon.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\Wordconv.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoasb.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\accicons.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Windows\svchost.com, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\SkypeSrv\SKYPESERVER.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WORDICON.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mpextms.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\identity_helper.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSQRY32.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Source user\OSE.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\OLicenseHeartbeat.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrBroker.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\AppSharingHookController64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\SELFCERT.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\SPREADSHEETCOMPARE.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_pwa_launcher.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\dbcicons.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.Loader.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\SCANPST.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\BHO\ie_to_edge_stub.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ORGCHART.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\VPREVIEW.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OcPubMgr.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Users\user\AppData\Local\Temp\chrome.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\PPTICO.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\wordicon.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\PerfBoost.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\AutoIt3\Aut2Exe\upx.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrSanBroker.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\officeappguardwin32.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOICONS.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\AutoIt3\Au3Info.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\AutoIt3\Au3Check.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\sscicons.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\140\SQLDumper.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\140\SQLDumper.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\140\SQLDumper.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLED.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\notification_click_helper.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\grv_icons.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\lyncicon.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\FLTLDR.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_proxy.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\osmclienticon.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\notification_helper.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pptico.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OLCFG.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pj11icon.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\xlicons.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ACCICONS.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE, type: DROPPED | Matched rule: Detects Neshta Author: ditekSHen |
Source: bWrRSlOThY.exe, type: SAMPLE | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: dump.pcap, type: PCAP | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 18.2.RemoteDestopManagerx86.exe.2997de0.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 18.2.RemoteDestopManagerx86.exe.2997de0.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 0.0.bWrRSlOThY.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: 29.2.RemoteDestopManagerx86.exe.2b37fac.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 29.2.RemoteDestopManagerx86.exe.2b37fac.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 29.2.RemoteDestopManagerx86.exe.2b48848.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 29.2.RemoteDestopManagerx86.exe.2b48848.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 2.2.bWrRSlOThY.exe.32c7dec.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 2.2.bWrRSlOThY.exe.32c7dec.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 2.2.bWrRSlOThY.exe.32d867c.0.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 2.2.bWrRSlOThY.exe.32d867c.0.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 18.2.RemoteDestopManagerx86.exe.29a8670.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 18.2.RemoteDestopManagerx86.exe.29a8670.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 19.2.RemoteDestopManagerx86.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 19.2.RemoteDestopManagerx86.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 2.2.bWrRSlOThY.exe.32d867c.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 2.2.bWrRSlOThY.exe.32d867c.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 18.2.RemoteDestopManagerx86.exe.2997de0.0.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 18.2.RemoteDestopManagerx86.exe.2997de0.0.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 18.2.RemoteDestopManagerx86.exe.29a8670.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 18.2.RemoteDestopManagerx86.exe.29a8670.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 29.2.RemoteDestopManagerx86.exe.2b48848.0.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 29.2.RemoteDestopManagerx86.exe.2b48848.0.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 2.2.bWrRSlOThY.exe.32c7dec.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 2.2.bWrRSlOThY.exe.32c7dec.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 29.2.RemoteDestopManagerx86.exe.2b37fac.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 29.2.RemoteDestopManagerx86.exe.2b37fac.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 0000001E.00000002.3408804926.0000000004CC8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000003.00000002.4617709059.000000000120E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000013.00000002.2815936645.0000000004DF8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000013.00000002.2813685167.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 00000013.00000002.2813685167.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 00000002.00000002.2164810535.00000000032C2000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 00000002.00000002.2164810535.00000000032C2000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 00000030.00000002.4609082147.0000000000866000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000012.00000002.2769868231.0000000002992000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 00000012.00000002.2769868231.0000000002992000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 00000027.00000002.4004536747.0000000000FBA000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000003.00000002.4617709059.00000000011A8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 0000001D.00000002.3361345490.0000000002B32000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 0000001D.00000002.3361345490.0000000002B32000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 00000003.00000002.4619895119.0000000002D41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000030.00000002.4611188210.000000000272F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000027.00000002.4005507938.0000000002AFF000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 0000001E.00000002.3398649421.0000000002681000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000013.00000002.2814476665.00000000028E1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: Process Memory Space: bWrRSlOThY.exe PID: 5332, type: MEMORYSTR | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: Process Memory Space: bWrRSlOThY.exe PID: 5100, type: MEMORYSTR | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: Process Memory Space: RemoteDestopManagerx86.exe PID: 2308, type: MEMORYSTR | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: Process Memory Space: RemoteDestopManagerx86.exe PID: 5332, type: MEMORYSTR | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: Process Memory Space: RemoteDestopManagerx86.exe PID: 5332, type: MEMORYSTR | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: Process Memory Space: RemoteDestopManagerx86.exe PID: 340, type: MEMORYSTR | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: Process Memory Space: RemoteDestopManagerx86.exe PID: 6476, type: MEMORYSTR | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: Process Memory Space: RemoteDestopManagerx86.exe PID: 760, type: MEMORYSTR | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: Process Memory Space: RemoteDestopManagerx86.exe PID: 1524, type: MEMORYSTR | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\AutoIt3\Uninstall.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\cookie_exporter.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\aimgr.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\DATABASECOMPARE.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\joticon.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\Wordconv.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoasb.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\accicons.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Windows\svchost.com, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\SkypeSrv\SKYPESERVER.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WORDICON.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mpextms.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\identity_helper.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSQRY32.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Source user\OSE.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\OLicenseHeartbeat.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrBroker.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\AppSharingHookController64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\SELFCERT.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\SPREADSHEETCOMPARE.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_pwa_launcher.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\dbcicons.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.Loader.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\SCANPST.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\BHO\ie_to_edge_stub.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ORGCHART.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\VPREVIEW.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OcPubMgr.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Users\user\AppData\Local\Temp\chrome.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\PPTICO.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\wordicon.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\PerfBoost.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\AutoIt3\Aut2Exe\upx.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrSanBroker.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\officeappguardwin32.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOICONS.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\AutoIt3\Au3Info.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\AutoIt3\Au3Check.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\sscicons.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\140\SQLDumper.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\140\SQLDumper.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\140\SQLDumper.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLED.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\notification_click_helper.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\grv_icons.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\lyncicon.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\FLTLDR.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_proxy.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\osmclienticon.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\notification_helper.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pptico.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OLCFG.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pj11icon.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\xlicons.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ACCICONS.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE, type: DROPPED | Matched rule: MALWARE_Win_Neshta author = ditekSHen, description = Detects Neshta |
Source: unknown | Process created: C:\Users\user\Desktop\bWrRSlOThY.exe "C:\Users\user\Desktop\bWrRSlOThY.exe" | |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process created: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe "C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe" | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process created: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe "C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe" | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C mkdir "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C copy "C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe" "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\svchost.com "C:\Windows\svchost.com" "C:\Users\user\AppData\Local\Temp\3582-490\REMOTE~1.EXE" | |
Source: C:\Windows\svchost.com | Process created: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe C:\Users\user\AppData\Local\Temp\3582-490\REMOTE~1.EXE | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe "C:\Users\user\AppData\Local\Temp\3582-490\REMOTE~1.EXE" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C mkdir "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C copy "C:\Users\user\AppData\Local\Temp\3582-490\REMOTE~1.EXE" "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C mkdir "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C copy "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C mkdir "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C copy "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C mkdir "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C copy "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process created: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe "C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process created: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe "C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C mkdir "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C copy "C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe" "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\svchost.com "C:\Windows\svchost.com" "C:\Users\user\AppData\Local\Temp\3582-490\REMOTE~1.EXE" | Jump to behavior |
Source: C:\Windows\svchost.com | Process created: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe C:\Users\user\AppData\Local\Temp\3582-490\REMOTE~1.EXE | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process created: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe "C:\Users\user\AppData\Local\Temp\3582-490\REMOTE~1.EXE" | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C mkdir "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86" | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C copy "C:\Users\user\AppData\Local\Temp\3582-490\REMOTE~1.EXE" "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C mkdir "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86" | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C copy "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C mkdir "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86" | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C copy "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C mkdir "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86" | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C copy "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" "C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe'" /f | |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: cryptnet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\svchost.com | Section loaded: apphelp.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: apphelp.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: xmllite.dll | |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: xmllite.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: xmllite.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: xmllite.dll | |
Source: Yara match | File source: bWrRSlOThY.exe, type: SAMPLE |
Source: Yara match | File source: 0.0.bWrRSlOThY.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000000.00000002.2592455877.0000000000409000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: bWrRSlOThY.exe PID: 3884, type: MEMORYSTR |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Uninstall.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\cookie_exporter.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\aimgr.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\DATABASECOMPARE.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\joticon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\Wordconv.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoasb.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\accicons.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\svchost.com, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SkypeSrv\SKYPESERVER.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\WORDICON.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mpextms.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\identity_helper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSQRY32.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Source user\OSE.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\OLicenseHeartbeat.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrBroker.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\AppSharingHookController64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SELFCERT.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\SPREADSHEETCOMPARE.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_pwa_launcher.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\dbcicons.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.Loader.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SCANPST.EXE, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\BHO\ie_to_edge_stub.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ORGCHART.EXE, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\VPREVIEW.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\OcPubMgr.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe, type: DROPPED |
Source: Yara match | File source: C:\Users\user\AppData\Local\Temp\chrome.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\PPTICO.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\wordicon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\PerfBoost.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Aut2Exe\upx.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrSanBroker.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\officeappguardwin32.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOICONS.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Au3Info.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Au3Check.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\sscicons.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\140\SQLDumper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLED.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\notification_click_helper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\grv_icons.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\lyncicon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\FLTLDR.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_proxy.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\osmclienticon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\notification_helper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pptico.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\OLCFG.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pj11icon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\xlicons.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ACCICONS.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE, type: DROPPED |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\PerfBoost.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpCmdRun.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\MSOHTMED.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-006E-0409-0000-0000000FF1CE}\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-0C0A-0000-0000000FF1CE}\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_pwa_launcher.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\FLTLDR.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SELFCERT.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SCANPST.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\xlicons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCopyAccelerator.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_proxy.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\accicons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\lyncicon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Users\user\AppData\Local\Temp\chrome.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\notification_click_helper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\officeappguardwin32.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\wordicon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\SPREADSHEETCOMPARE.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ConfigSecurityPolicy.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pj11icon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ACCICONS.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\AppSharingHookController64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\elevation_service.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\joticon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SkypeSrv\SKYPESERVER.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\Install\{EB80938B-EC00-4683-A2CC-456206E3A4E1}\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mpextms.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge_pwa_launcher.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\cookie_exporter.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-0409-0000-0000000FF1CE}\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\BHO\ie_to_edge_stub.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pptico.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\dbcicons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSQRY32.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-040C-0000-0000000FF1CE}\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ORGCHART.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\PPTICO.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\osmclienticon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\WORDICON.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrSanBroker.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\upx.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\Uninstall.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\sscicons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpCmdRun.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\cookie_exporter.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\notification_helper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLED.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mpextms.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrBroker.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\Wordconv.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlpCmd.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\pwahelper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\OcPubMgr.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\aimgr.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.Loader.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\VPREVIEW.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\OLCFG.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\grv_icons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoasb.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\identity_helper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\DATABASECOMPARE.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedgewebview2.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\PerfBoost.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpCmdRun.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\MSOHTMED.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLED.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-006E-0409-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Windows\svchost.com | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-0C0A-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_pwa_launcher.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\cmd.exe | File created: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\FLTLDR.EXE | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | File created: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\aimgr.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\SELFCERT.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\SCANPST.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\xlicons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCopyAccelerator.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_proxy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\identity_helper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\accicons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\lyncicon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge_proxy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Users\user\AppData\Local\Temp\chrome.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\140\SQLDumper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\notification_click_helper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\officeappguardwin32.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\wordicon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\SPREADSHEETCOMPARE.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ConfigSecurityPolicy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pj11icon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\ACCICONS.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOICONS.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\AppSharingHookController64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\elevation_service.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\joticon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\SkypeSrv\SKYPESERVER.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Google\Update\Install\{EB80938B-EC00-4683-A2CC-456206E3A4E1}\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mpextms.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge_pwa_launcher.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Mozilla Maintenance Service\Uninstall.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\ai.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\cookie_exporter.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-0409-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\Installer\setup.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\BHO\ie_to_edge_stub.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pptico.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\dbcicons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\MSQRY32.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-040C-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\ORGCHART.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\PPTICO.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\osmclienticon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\WORDICON.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrSanBroker.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\AutoIt3\Aut2Exe\upx.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\AutoIt3\Uninstall.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\sscicons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpCmdRun.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLED.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\cookie_exporter.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\notification_helper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mpextms.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrBroker.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\Wordconv.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlpCmd.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\pwahelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\OcPubMgr.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\aimgr.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.Loader.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\VPREVIEW.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\OLicenseHeartbeat.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\OLCFG.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\grv_icons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Source user\OSE.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\msoasb.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\identity_helper.exe | Jump to dropped file |
Source: Yara match | File source: bWrRSlOThY.exe, type: SAMPLE |
Source: Yara match | File source: 0.0.bWrRSlOThY.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000000.00000002.2592455877.0000000000409000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: bWrRSlOThY.exe PID: 3884, type: MEMORYSTR |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Uninstall.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\cookie_exporter.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\aimgr.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\DATABASECOMPARE.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\joticon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\Wordconv.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoasb.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\accicons.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\svchost.com, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SkypeSrv\SKYPESERVER.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\WORDICON.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mpextms.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\identity_helper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSQRY32.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Source user\OSE.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\OLicenseHeartbeat.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrBroker.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\AppSharingHookController64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SELFCERT.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\SPREADSHEETCOMPARE.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_pwa_launcher.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\dbcicons.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.Loader.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SCANPST.EXE, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\BHO\ie_to_edge_stub.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ORGCHART.EXE, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\VPREVIEW.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\OcPubMgr.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe, type: DROPPED |
Source: Yara match | File source: C:\Users\user\AppData\Local\Temp\chrome.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\PPTICO.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\wordicon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\PerfBoost.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Aut2Exe\upx.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrSanBroker.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\officeappguardwin32.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOICONS.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Au3Info.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Au3Check.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\sscicons.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\140\SQLDumper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLED.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\notification_click_helper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\grv_icons.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\lyncicon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\FLTLDR.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_proxy.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\osmclienticon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\notification_helper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pptico.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\OLCFG.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pj11icon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\xlicons.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ACCICONS.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE, type: DROPPED |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\3582-490\bWrRSlOThY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\svchost.com | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\3582-490\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\RemoteDestopManagerx86\RemoteDestopManagerx86.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\DATABASECOMPARE.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedgewebview2.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\PerfBoost.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpCmdRun.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\MSOHTMED.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLED.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-006E-0409-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-0C0A-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_pwa_launcher.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\FLTLDR.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\aimgr.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\SELFCERT.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\SCANPST.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\xlicons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCopyAccelerator.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_proxy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\identity_helper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\accicons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\lyncicon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge_proxy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\chrome.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\140\SQLDumper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\notification_click_helper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\officeappguardwin32.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\wordicon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\SPREADSHEETCOMPARE.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ConfigSecurityPolicy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pj11icon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\ACCICONS.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOICONS.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\AppSharingHookController64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\elevation_service.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\joticon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\SkypeSrv\SKYPESERVER.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\Install\{EB80938B-EC00-4683-A2CC-456206E3A4E1}\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mpextms.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge_pwa_launcher.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Mozilla Maintenance Service\Uninstall.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\ai.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\cookie_exporter.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-0409-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\Installer\setup.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\BHO\ie_to_edge_stub.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pptico.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\dbcicons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\MSQRY32.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-040C-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\ORGCHART.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\osmclienticon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\PPTICO.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\WORDICON.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrSanBroker.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Aut2Exe\upx.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Uninstall.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\sscicons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpCmdRun.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLED.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\notification_helper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\cookie_exporter.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mpextms.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrBroker.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\Wordconv.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlpCmd.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\pwahelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\OcPubMgr.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\aimgr.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.Loader.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\OLicenseHeartbeat.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\VPREVIEW.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\OLCFG.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\grv_icons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Source user\OSE.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\msoasb.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\identity_helper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\bWrRSlOThY.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to dropped file |
Source: Yara match | File source: bWrRSlOThY.exe, type: SAMPLE |
Source: Yara match | File source: 0.0.bWrRSlOThY.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000000.00000002.2592455877.0000000000409000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: bWrRSlOThY.exe PID: 3884, type: MEMORYSTR |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Uninstall.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\cookie_exporter.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\aimgr.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\DATABASECOMPARE.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\joticon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\Wordconv.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoasb.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\accicons.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\svchost.com, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SkypeSrv\SKYPESERVER.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\WORDICON.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mpextms.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\identity_helper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSQRY32.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Source user\OSE.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\OLicenseHeartbeat.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrBroker.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\AppSharingHookController64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SELFCERT.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\SPREADSHEETCOMPARE.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_pwa_launcher.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\dbcicons.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.Loader.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SCANPST.EXE, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\BHO\ie_to_edge_stub.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ORGCHART.EXE, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\VPREVIEW.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\OcPubMgr.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe, type: DROPPED |
Source: Yara match | File source: C:\Users\user\AppData\Local\Temp\chrome.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\PPTICO.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\wordicon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\PerfBoost.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Aut2Exe\upx.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrSanBroker.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\officeappguardwin32.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOICONS.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Au3Info.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Au3Check.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\sscicons.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\140\SQLDumper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLED.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\notification_click_helper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\grv_icons.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\lyncicon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\FLTLDR.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_proxy.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\osmclienticon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\notification_helper.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pptico.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\OLCFG.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pj11icon.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\xlicons.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Office16\ACCICONS.EXE, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe, type: DROPPED |
Source: Yara match | File source: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE, type: DROPPED |