Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Code function: 4_2_00F41000 LocalAlloc,LocalAlloc,GetModuleFileNameW,CertOpenSystemStoreA,LocalAlloc,LocalAlloc,CryptQueryObject,LocalFree,CryptMsgGetParam,CryptMsgGetParam,LocalAlloc,LocalAlloc,CryptMsgGetParam,CertCreateCertificateContext,CertAddCertificateContextToStore,CertFreeCertificateContext,LocalFree,CryptMsgGetParam,LocalFree,LocalFree,CryptMsgGetParam,CryptMsgGetParam,CertFindAttribute,CertFindAttribute,CertFindAttribute,LoadLibraryA,GetProcAddress,Sleep,CertDeleteCertificateFromStore,CertDeleteCertificateFromStore,CertCloseStore,LocalFree,LocalFree,LocalFree, |
4_2_00F41000 |
Source: |
Binary string: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb source: Scan_PDF_3008059384.exe |
Source: |
Binary string: b.pdbJ: source: dfsvc.exe, 00000005.00000002.2036763574.0000019EA7E1E000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdbz source: dfsvc.exe, 00000005.00000002.2036665985.0000019EA7DB6000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.pdb source: dfsvc.exe, 00000005.00000002.2035229255.0000019E8DA84000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: lture=en, PublicKeyToken=b03f5f7f11d50a3aem.pdb source: dfsvc.exe, 00000005.00000002.2036665985.0000019EA7DB6000.00000004.00000020.00020000.00000000.sdmp |
Source: Scan_PDF_3008059384.exe, 00000004.00000003.1284708860.00000000006CB000.00000004.00000020.00020000.00000000.sdmp, Scan_PDF_3008059384.exe, 00000004.00000002.1285669681.00000000006CB000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredID |
Source: Scan_PDF_3008059384.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: Scan_PDF_3008059384.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: Scan_PDF_3008059384.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: Scan_PDF_3008059384.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: Scan_PDF_3008059384.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: Scan_PDF_3008059384.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: Scan_PDF_3008059384.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: Scan_PDF_3008059384.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: Scan_PDF_3008059384.exe |
String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: dfsvc.exe, 00000005.00000002.2037336189.0000019EA841D000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://iptc.org/std/Iptc4xmpCore/1.0/xmlns/Mic |
Source: dfsvc.exe, 00000005.00000002.2037336189.0000019EA841D000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ns.adobe. |
Source: Scan_PDF_3008059384.exe |
String found in binary or memory: http://ocsp.digicert.com0 |
Source: Scan_PDF_3008059384.exe |
String found in binary or memory: http://ocsp.digicert.com0A |
Source: Scan_PDF_3008059384.exe |
String found in binary or memory: http://ocsp.digicert.com0C |
Source: Scan_PDF_3008059384.exe |
String found in binary or memory: http://ocsp.digicert.com0X |
Source: dfsvc.exe, 00000005.00000002.2035838213.0000019E8F78E000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: Scan_PDF_3008059384.exe |
String found in binary or memory: http://www.digicert.com/CPS0 |
Source: dfsvc.exe, 00000005.00000002.2035838213.0000019E8F832000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://app.cloudfiles-secure.io |
Source: Scan_PDF_3008059384.exe, 00000004.00000003.1284708860.00000000006CB000.00000004.00000020.00020000.00000000.sdmp, Scan_PDF_3008059384.exe, 00000004.00000002.1285669681.00000000006CB000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://app.cloudfiles-secure.io/Bin/ScreenConnect.Client.a |
Source: dfsvc.exe, 00000005.00000002.2035838213.0000019E8F890000.00000004.00000800.00020000.00000000.sdmp, dfsvc.exe, 00000005.00000002.2035838213.0000019E8F83A000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://app.cloudfiles-secure.io/Bin/ScreenConnect.Client.application?e=Support&y= |
Source: B96Z294P.log.5.dr |
String found in binary or memory: https://app.cloudfiles-secure.io/Bin/ScreenConnect.Client.application?e=Support&y=Guest&h=kkl22.ddns |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Code function: 4_2_00F4A495 |
4_2_00F4A495 |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Code function: 5_2_00007FF7C0E4AEF5 |
5_2_00007FF7C0E4AEF5 |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Code function: 5_2_00007FF7C0E51FB6 |
5_2_00007FF7C0E51FB6 |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Code function: 5_2_00007FF7C0E41240 |
5_2_00007FF7C0E41240 |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Code function: 5_2_00007FF7C0E4F441 |
5_2_00007FF7C0E4F441 |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Code function: 4_2_00F41000 LocalAlloc,LocalAlloc,GetModuleFileNameW,CertOpenSystemStoreA,LocalAlloc,LocalAlloc,CryptQueryObject,LocalFree,CryptMsgGetParam,CryptMsgGetParam,LocalAlloc,LocalAlloc,CryptMsgGetParam,CertCreateCertificateContext,CertAddCertificateContextToStore,CertFreeCertificateContext,LocalFree,CryptMsgGetParam,LocalFree,LocalFree,CryptMsgGetParam,CryptMsgGetParam,CertFindAttribute,CertFindAttribute,CertFindAttribute,LoadLibraryA,GetProcAddress,Sleep,CertDeleteCertificateFromStore,CertDeleteCertificateFromStore,CertCloseStore,LocalFree,LocalFree,LocalFree, |
4_2_00F41000 |
Source: unknown |
Process created: C:\Users\user\Desktop\Scan_PDF_3008059384.exe "C:\Users\user\Desktop\Scan_PDF_3008059384.exe" |
|
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe" |
|
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Section loaded: dfshim.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: dfshim.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: dwrite.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: uiautomationcore.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: Scan_PDF_3008059384.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT |
Source: Scan_PDF_3008059384.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE |
Source: Scan_PDF_3008059384.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC |
Source: Scan_PDF_3008059384.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: Scan_PDF_3008059384.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG |
Source: Scan_PDF_3008059384.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT |
Source: |
Binary string: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb source: Scan_PDF_3008059384.exe |
Source: |
Binary string: b.pdbJ: source: dfsvc.exe, 00000005.00000002.2036763574.0000019EA7E1E000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdbz source: dfsvc.exe, 00000005.00000002.2036665985.0000019EA7DB6000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.pdb source: dfsvc.exe, 00000005.00000002.2035229255.0000019E8DA84000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: lture=en, PublicKeyToken=b03f5f7f11d50a3aem.pdb source: dfsvc.exe, 00000005.00000002.2036665985.0000019EA7DB6000.00000004.00000020.00020000.00000000.sdmp |
Source: Scan_PDF_3008059384.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: Scan_PDF_3008059384.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: Scan_PDF_3008059384.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: Scan_PDF_3008059384.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: Scan_PDF_3008059384.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Code function: 4_2_00F41000 LocalAlloc,LocalAlloc,GetModuleFileNameW,CertOpenSystemStoreA,LocalAlloc,LocalAlloc,CryptQueryObject,LocalFree,CryptMsgGetParam,CryptMsgGetParam,LocalAlloc,LocalAlloc,CryptMsgGetParam,CertCreateCertificateContext,CertAddCertificateContextToStore,CertFreeCertificateContext,LocalFree,CryptMsgGetParam,LocalFree,LocalFree,CryptMsgGetParam,CryptMsgGetParam,CertFindAttribute,CertFindAttribute,CertFindAttribute,LoadLibraryA,GetProcAddress,Sleep,CertDeleteCertificateFromStore,CertDeleteCertificateFromStore,CertCloseStore,LocalFree,LocalFree,LocalFree, |
4_2_00F41000 |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Code function: 4_2_00F41BC0 push ecx; ret |
4_2_00F41BD3 |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Code function: 5_2_00007FF7C0E4B92B push cs; iretd |
5_2_00007FF7C0E4B96A |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Code function: 5_2_00007FF7C0E4845E push eax; ret |
5_2_00007FF7C0E4846D |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Code function: 5_2_00007FF7C0E4842E pushad ; ret |
5_2_00007FF7C0E4845D |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Code function: 5_2_00007FF7C0E47C35 push eax; retf |
5_2_00007FF7C0E47C6D |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Code function: 5_2_00007FF7C0E400BD pushad ; iretd |
5_2_00007FF7C0E400C1 |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Code function: 5_2_00007FF7C0E47018 push cs; iretd |
5_2_00007FF7C0E4701F |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 599860 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 599735 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 599625 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 599512 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 599404 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 599297 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 599172 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 599063 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 598878 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 598728 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 598538 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 598360 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 598219 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 598103 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597984 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597875 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597766 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597656 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597547 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597438 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597313 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597188 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597077 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 596969 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 596844 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 596735 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 596610 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 596485 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 596360 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 596235 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 596110 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595971 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595844 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595731 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595625 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595516 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595406 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595297 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595188 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595063 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594938 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594813 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594700 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594593 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594484 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594375 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594266 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594141 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594031 |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe TID: 8188 |
Thread sleep time: -40000s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -26747778906878833s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -600000s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -599860s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -599735s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -599625s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -599512s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -599404s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -599297s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -599172s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -599063s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -598878s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -598728s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -598538s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -598360s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -598219s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -598103s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -597984s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -597875s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -597766s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -597656s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -597547s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -597438s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -597313s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -597188s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -597077s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -596969s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -596844s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -596735s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -596610s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -596485s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -596360s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -596235s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -596110s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -595971s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -595844s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -595731s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -595625s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -595516s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -595406s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -595297s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -595188s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -595063s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -594938s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -594813s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -594700s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -594593s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -594484s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -594375s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -594266s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -594141s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 |
Thread sleep time: -594031s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Thread delayed: delay time: 40000 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 599860 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 599735 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 599625 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 599512 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 599404 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 599297 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 599172 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 599063 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 598878 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 598728 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 598538 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 598360 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 598219 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 598103 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597984 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597875 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597766 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597656 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597547 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597438 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597313 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597188 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 597077 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 596969 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 596844 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 596735 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 596610 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 596485 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 596360 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 596235 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 596110 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595971 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595844 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595731 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595625 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595516 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595406 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595297 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595188 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 595063 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594938 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594813 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594700 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594593 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594484 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594375 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594266 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594141 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe |
Thread delayed: delay time: 594031 |
Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Code function: 4_2_00F41000 LocalAlloc,LocalAlloc,GetModuleFileNameW,CertOpenSystemStoreA,LocalAlloc,LocalAlloc,CryptQueryObject,LocalFree,CryptMsgGetParam,CryptMsgGetParam,LocalAlloc,LocalAlloc,CryptMsgGetParam,CertCreateCertificateContext,CertAddCertificateContextToStore,CertFreeCertificateContext,LocalFree,CryptMsgGetParam,LocalFree,LocalFree,CryptMsgGetParam,CryptMsgGetParam,CertFindAttribute,CertFindAttribute,CertFindAttribute,LoadLibraryA,GetProcAddress,Sleep,CertDeleteCertificateFromStore,CertDeleteCertificateFromStore,CertCloseStore,LocalFree,LocalFree,LocalFree, |
4_2_00F41000 |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Code function: 4_2_00F41493 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
4_2_00F41493 |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Code function: 4_2_00F44573 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
4_2_00F44573 |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Code function: 4_2_00F4191F IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
4_2_00F4191F |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe |
Code function: 4_2_00F41AAC SetUnhandledExceptionFilter, |
4_2_00F41AAC |