Click to jump to signature section
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Code function: 4_2_00F41000 LocalAlloc,LocalAlloc,GetModuleFileNameW,CertOpenSystemStoreA,LocalAlloc,LocalAlloc,CryptQueryObject,LocalFree,CryptMsgGetParam,CryptMsgGetParam,LocalAlloc,LocalAlloc,CryptMsgGetParam,CertCreateCertificateContext,CertAddCertificateContextToStore,CertFreeCertificateContext,LocalFree,CryptMsgGetParam,LocalFree,LocalFree,CryptMsgGetParam,CryptMsgGetParam,CertFindAttribute,CertFindAttribute,CertFindAttribute,LoadLibraryA,GetProcAddress,Sleep,CertDeleteCertificateFromStore,CertDeleteCertificateFromStore,CertCloseStore,LocalFree,LocalFree,LocalFree, | 4_2_00F41000 |
Source: | Binary string: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb source: Scan_PDF_3008059384.exe |
Source: | Binary string: b.pdbJ: source: dfsvc.exe, 00000005.00000002.2036763574.0000019EA7E1E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdbz source: dfsvc.exe, 00000005.00000002.2036665985.0000019EA7DB6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.pdb source: dfsvc.exe, 00000005.00000002.2035229255.0000019E8DA84000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: lture=en, PublicKeyToken=b03f5f7f11d50a3aem.pdb source: dfsvc.exe, 00000005.00000002.2036665985.0000019EA7DB6000.00000004.00000020.00020000.00000000.sdmp |
Source: Scan_PDF_3008059384.exe, 00000004.00000003.1284708860.00000000006CB000.00000004.00000020.00020000.00000000.sdmp, Scan_PDF_3008059384.exe, 00000004.00000002.1285669681.00000000006CB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredID |
Source: Scan_PDF_3008059384.exe | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: Scan_PDF_3008059384.exe | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: Scan_PDF_3008059384.exe | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: Scan_PDF_3008059384.exe | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: Scan_PDF_3008059384.exe | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: Scan_PDF_3008059384.exe | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: Scan_PDF_3008059384.exe | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: Scan_PDF_3008059384.exe | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: Scan_PDF_3008059384.exe | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: dfsvc.exe, 00000005.00000002.2037336189.0000019EA841D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://iptc.org/std/Iptc4xmpCore/1.0/xmlns/Mic |
Source: dfsvc.exe, 00000005.00000002.2037336189.0000019EA841D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ns.adobe. |
Source: Scan_PDF_3008059384.exe | String found in binary or memory: http://ocsp.digicert.com0 |
Source: Scan_PDF_3008059384.exe | String found in binary or memory: http://ocsp.digicert.com0A |
Source: Scan_PDF_3008059384.exe | String found in binary or memory: http://ocsp.digicert.com0C |
Source: Scan_PDF_3008059384.exe | String found in binary or memory: http://ocsp.digicert.com0X |
Source: dfsvc.exe, 00000005.00000002.2035838213.0000019E8F78E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: Scan_PDF_3008059384.exe | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: dfsvc.exe, 00000005.00000002.2035838213.0000019E8F832000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://app.cloudfiles-secure.io |
Source: Scan_PDF_3008059384.exe, 00000004.00000003.1284708860.00000000006CB000.00000004.00000020.00020000.00000000.sdmp, Scan_PDF_3008059384.exe, 00000004.00000002.1285669681.00000000006CB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://app.cloudfiles-secure.io/Bin/ScreenConnect.Client.a |
Source: dfsvc.exe, 00000005.00000002.2035838213.0000019E8F890000.00000004.00000800.00020000.00000000.sdmp, dfsvc.exe, 00000005.00000002.2035838213.0000019E8F83A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://app.cloudfiles-secure.io/Bin/ScreenConnect.Client.application?e=Support&y= |
Source: B96Z294P.log.5.dr | String found in binary or memory: https://app.cloudfiles-secure.io/Bin/ScreenConnect.Client.application?e=Support&y=Guest&h=kkl22.ddns |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Code function: 4_2_00F4A495 | 4_2_00F4A495 |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Code function: 5_2_00007FF7C0E4AEF5 | 5_2_00007FF7C0E4AEF5 |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Code function: 5_2_00007FF7C0E51FB6 | 5_2_00007FF7C0E51FB6 |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Code function: 5_2_00007FF7C0E41240 | 5_2_00007FF7C0E41240 |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Code function: 5_2_00007FF7C0E4F441 | 5_2_00007FF7C0E4F441 |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Code function: 4_2_00F41000 LocalAlloc,LocalAlloc,GetModuleFileNameW,CertOpenSystemStoreA,LocalAlloc,LocalAlloc,CryptQueryObject,LocalFree,CryptMsgGetParam,CryptMsgGetParam,LocalAlloc,LocalAlloc,CryptMsgGetParam,CertCreateCertificateContext,CertAddCertificateContextToStore,CertFreeCertificateContext,LocalFree,CryptMsgGetParam,LocalFree,LocalFree,CryptMsgGetParam,CryptMsgGetParam,CertFindAttribute,CertFindAttribute,CertFindAttribute,LoadLibraryA,GetProcAddress,Sleep,CertDeleteCertificateFromStore,CertDeleteCertificateFromStore,CertCloseStore,LocalFree,LocalFree,LocalFree, | 4_2_00F41000 |
Source: unknown | Process created: C:\Users\user\Desktop\Scan_PDF_3008059384.exe "C:\Users\user\Desktop\Scan_PDF_3008059384.exe" | |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe" | |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe" | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Section loaded: dfshim.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: dfshim.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: uiautomationcore.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Section loaded: propsys.dll | Jump to behavior |
Source: Scan_PDF_3008059384.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT |
Source: Scan_PDF_3008059384.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE |
Source: Scan_PDF_3008059384.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC |
Source: Scan_PDF_3008059384.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: Scan_PDF_3008059384.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG |
Source: Scan_PDF_3008059384.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT |
Source: | Binary string: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb source: Scan_PDF_3008059384.exe |
Source: | Binary string: b.pdbJ: source: dfsvc.exe, 00000005.00000002.2036763574.0000019EA7E1E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdbz source: dfsvc.exe, 00000005.00000002.2036665985.0000019EA7DB6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.pdb source: dfsvc.exe, 00000005.00000002.2035229255.0000019E8DA84000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: lture=en, PublicKeyToken=b03f5f7f11d50a3aem.pdb source: dfsvc.exe, 00000005.00000002.2036665985.0000019EA7DB6000.00000004.00000020.00020000.00000000.sdmp |
Source: Scan_PDF_3008059384.exe | Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: Scan_PDF_3008059384.exe | Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: Scan_PDF_3008059384.exe | Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: Scan_PDF_3008059384.exe | Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: Scan_PDF_3008059384.exe | Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Code function: 4_2_00F41000 LocalAlloc,LocalAlloc,GetModuleFileNameW,CertOpenSystemStoreA,LocalAlloc,LocalAlloc,CryptQueryObject,LocalFree,CryptMsgGetParam,CryptMsgGetParam,LocalAlloc,LocalAlloc,CryptMsgGetParam,CertCreateCertificateContext,CertAddCertificateContextToStore,CertFreeCertificateContext,LocalFree,CryptMsgGetParam,LocalFree,LocalFree,CryptMsgGetParam,CryptMsgGetParam,CertFindAttribute,CertFindAttribute,CertFindAttribute,LoadLibraryA,GetProcAddress,Sleep,CertDeleteCertificateFromStore,CertDeleteCertificateFromStore,CertCloseStore,LocalFree,LocalFree,LocalFree, | 4_2_00F41000 |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Code function: 4_2_00F41BC0 push ecx; ret | 4_2_00F41BD3 |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Code function: 5_2_00007FF7C0E4B92B push cs; iretd | 5_2_00007FF7C0E4B96A |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Code function: 5_2_00007FF7C0E4845E push eax; ret | 5_2_00007FF7C0E4846D |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Code function: 5_2_00007FF7C0E4842E pushad ; ret | 5_2_00007FF7C0E4845D |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Code function: 5_2_00007FF7C0E47C35 push eax; retf | 5_2_00007FF7C0E47C6D |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Code function: 5_2_00007FF7C0E400BD pushad ; iretd | 5_2_00007FF7C0E400C1 |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Code function: 5_2_00007FF7C0E47018 push cs; iretd | 5_2_00007FF7C0E4701F |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 599860 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 599735 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 599625 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 599512 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 599404 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 599297 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 599172 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 599063 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 598878 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 598728 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 598538 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 598360 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 598219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 598103 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597984 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597875 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597766 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597438 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597313 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597188 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597077 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 596969 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 596844 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 596735 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 596610 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 596485 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 596360 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 596235 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 596110 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595971 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595844 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595731 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595625 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595516 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595406 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595297 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595188 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595063 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594938 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594813 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594700 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594593 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594484 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594375 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594266 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594141 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594031 | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe TID: 8188 | Thread sleep time: -40000s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -26747778906878833s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -599860s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -599735s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -599625s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -599512s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -599404s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -599297s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -599172s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -599063s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -598878s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -598728s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -598538s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -598360s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -598219s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -598103s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -597984s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -597875s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -597766s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -597656s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -597547s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -597438s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -597313s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -597188s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -597077s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -596969s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -596844s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -596735s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -596610s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -596485s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -596360s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -596235s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -596110s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -595971s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -595844s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -595731s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -595625s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -595516s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -595406s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -595297s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -595188s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -595063s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -594938s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -594813s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -594700s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -594593s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -594484s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -594375s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -594266s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -594141s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 7404 | Thread sleep time: -594031s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Thread delayed: delay time: 40000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 599860 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 599735 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 599625 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 599512 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 599404 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 599297 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 599172 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 599063 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 598878 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 598728 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 598538 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 598360 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 598219 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 598103 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597984 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597875 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597766 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597656 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597547 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597438 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597313 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597188 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 597077 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 596969 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 596844 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 596735 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 596610 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 596485 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 596360 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 596235 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 596110 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595971 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595844 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595731 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595625 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595516 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595406 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595297 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595188 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 595063 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594938 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594813 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594700 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594593 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594484 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594375 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594266 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594141 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe | Thread delayed: delay time: 594031 | Jump to behavior |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Code function: 4_2_00F41000 LocalAlloc,LocalAlloc,GetModuleFileNameW,CertOpenSystemStoreA,LocalAlloc,LocalAlloc,CryptQueryObject,LocalFree,CryptMsgGetParam,CryptMsgGetParam,LocalAlloc,LocalAlloc,CryptMsgGetParam,CertCreateCertificateContext,CertAddCertificateContextToStore,CertFreeCertificateContext,LocalFree,CryptMsgGetParam,LocalFree,LocalFree,CryptMsgGetParam,CryptMsgGetParam,CertFindAttribute,CertFindAttribute,CertFindAttribute,LoadLibraryA,GetProcAddress,Sleep,CertDeleteCertificateFromStore,CertDeleteCertificateFromStore,CertCloseStore,LocalFree,LocalFree,LocalFree, | 4_2_00F41000 |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Code function: 4_2_00F41493 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 4_2_00F41493 |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Code function: 4_2_00F44573 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 4_2_00F44573 |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Code function: 4_2_00F4191F IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 4_2_00F4191F |
Source: C:\Users\user\Desktop\Scan_PDF_3008059384.exe | Code function: 4_2_00F41AAC SetUnhandledExceptionFilter, | 4_2_00F41AAC |