Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_00404069 |
2_2_00404069 |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_0040A8DB |
2_2_0040A8DB |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_00406550 |
2_2_00406550 |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_0040B965 |
2_2_0040B965 |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_00403D17 |
2_2_00403D17 |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_004035D5 |
2_2_004035D5 |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_004039DA |
2_2_004039DA |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_004159BF |
2_2_004159BF |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_0040866E |
2_2_0040866E |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_00407E7F |
2_2_00407E7F |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_0040AECE |
2_2_0040AECE |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_004042F0 |
2_2_004042F0 |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_00410334 |
2_2_00410334 |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_0040A3BD |
2_2_0040A3BD |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_1000A69F |
2_2_1000A69F |
Source: C:\Users\user\Desktop\test.exe |
Code function: 3_2_00407753 |
3_2_00407753 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Code function: 8_2_1000A69F |
8_2_1000A69F |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_0040247F |
11_2_0040247F |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_004074EC |
11_2_004074EC |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_00402142 |
11_2_00402142 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_00401D3D |
11_2_00401D3D |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_0040C1C4 |
11_2_0040C1C4 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_00404DCD |
11_2_00404DCD |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_004055BC |
11_2_004055BC |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_00402A58 |
11_2_00402A58 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_00407A68 |
11_2_00407A68 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_00406FCE |
11_2_00406FCE |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_004027D1 |
11_2_004027D1 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_0040FF99 |
11_2_0040FF99 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_1000A69F |
11_2_1000A69F |
Source: C:\Users\user\AppData\Local\Temp\wtmps.exe |
Code function: 14_2_00407F2C |
14_2_00407F2C |
Source: C:\Users\user\AppData\Local\Temp\wtmps.exe |
Code function: 14_2_004015A0 |
14_2_004015A0 |
Source: C:\Windows\SysWOW64\mscaps.exe |
Code function: 15_2_00401F70 |
15_2_00401F70 |
Source: C:\Windows\SysWOW64\mscaps.exe |
Code function: 15_2_0040A13C |
15_2_0040A13C |
Source: C:\Windows\SysWOW64\mscaps.exe |
Code function: 15_2_004071EE |
15_2_004071EE |
Source: unknown |
Process created: C:\Users\user\Desktop\test.exe "C:\Users\user\Desktop\test.exe" |
|
Source: C:\Users\user\Desktop\test.exe |
Process created: C:\Windows\SysWOW64\explorer.exe explorer.exe |
|
Source: C:\Windows\SysWOW64\explorer.exe |
Process created: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe "C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe" |
|
Source: C:\Windows\SysWOW64\explorer.exe |
Process created: C:\Users\user\Desktop\test.exe "C:\Users\user\Desktop\test.exe" |
|
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Roaming\Temp\user0.bat" " |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Roaming\Temp\user1.bat" " |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe "C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe" |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Roaming\Temp\user1.bat" " |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe "C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe" /i 6788 |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Roaming\Temp\user2.bat" " |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\Temp\wtmps.exe "C:\Users\user\AppData\Local\Temp\wtmps.exe" |
|
Source: C:\Users\user\AppData\Local\Temp\wtmps.exe |
Process created: C:\Windows\SysWOW64\mscaps.exe "C:\Windows\system32\mscaps.exe" /C:\Users\user\AppData\Local\Temp\wtmps.exe |
|
Source: C:\Users\user\Desktop\test.exe |
Process created: C:\Windows\SysWOW64\explorer.exe explorer.exe |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process created: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe "C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe" |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process created: C:\Users\user\Desktop\test.exe "C:\Users\user\Desktop\test.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Roaming\Temp\user0.bat" " |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Roaming\Temp\user1.bat" " |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe "C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Roaming\Temp\user1.bat" " |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe "C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe" /i 6788 |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Roaming\Temp\user2.bat" " |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\Temp\wtmps.exe "C:\Users\user\AppData\Local\Temp\wtmps.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\wtmps.exe |
Process created: C:\Windows\SysWOW64\mscaps.exe "C:\Windows\system32\mscaps.exe" /C:\Users\user\AppData\Local\Temp\wtmps.exe |
|
Source: C:\Users\user\Desktop\test.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: aepic.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: twinapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: powrprof.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: dxgi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: wtsapi32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: twinapi.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: umpdc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\test.exe |
Section loaded: qt5core.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\test.exe |
Section loaded: qt5gui.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\test.exe |
Section loaded: qt5opengl.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\test.exe |
Section loaded: qt5serialport.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\test.exe |
Section loaded: qt5widgets.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\test.exe |
Section loaded: qt5winextras.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\test.exe |
Section loaded: libgcc_s_dw2-1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\test.exe |
Section loaded: libstdc++-6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: cmdext.dll |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: apphelp.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: aclayers.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: sfc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: aclayers.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: sfc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\wtmps.exe |
Section loaded: apphelp.dll |
|
Source: C:\Users\user\AppData\Local\Temp\wtmps.exe |
Section loaded: aclayers.dll |
|
Source: C:\Users\user\AppData\Local\Temp\wtmps.exe |
Section loaded: mpr.dll |
|
Source: C:\Users\user\AppData\Local\Temp\wtmps.exe |
Section loaded: sfc.dll |
|
Source: C:\Users\user\AppData\Local\Temp\wtmps.exe |
Section loaded: sfc_os.dll |
|
Source: C:\Users\user\AppData\Local\Temp\wtmps.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Users\user\AppData\Local\Temp\wtmps.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\SysWOW64\mscaps.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\SysWOW64\mscaps.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\SysWOW64\mscaps.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Users\user\Desktop\test.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: __EH_prolog,GetComputerNameW,GetUserNameW,GetSystemDefaultLangID,GetAdaptersInfo,GetAdaptersInfo,MultiByteToWideChar,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryA,GetProcAddress,InternetGetConnectedState,FreeLibrary,GetTempPathW,GetTempFileNameW,GetTempFileNameW,GetTempFileNameW,WideCharToMultiByte,WideCharToMultiByte,WideCharToMultiByte, |
2_2_00402056 |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: GetAdaptersInfo,GetAdaptersInfo,inet_addr,inet_addr, |
2_2_00401CB0 |
Source: C:\Users\user\AppData\Local\Temp\wtmps.exe |
Code function: GetProcessHeap,GetProcessHeap,HeapAlloc,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,GetProcessHeap,HeapFree, |
14_2_00401D20 |
Source: C:\Windows\SysWOW64\mscaps.exe |
Code function: GetProcessHeap,GetProcessHeap,HeapAlloc,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,GetProcessHeap,HeapFree, |
15_2_00402600 |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_00411746 SetUnhandledExceptionFilter, |
2_2_00411746 |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_00411758 SetUnhandledExceptionFilter, |
2_2_00411758 |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_1000BA64 SetUnhandledExceptionFilter, |
2_2_1000BA64 |
Source: C:\Users\user\AppData\Local\Temp\@AE2AF6.tmp.exe |
Code function: 2_2_1000BA76 SetUnhandledExceptionFilter, |
2_2_1000BA76 |
Source: C:\Users\user\Desktop\test.exe |
Code function: 3_2_00401179 Sleep,Sleep,SetUnhandledExceptionFilter,_acmdln,malloc,strlen,malloc,memcpy,__initenv,_cexit,_amsg_exit,_initterm,GetStartupInfoA,_initterm,exit, |
3_2_00401179 |
Source: C:\Users\user\Desktop\test.exe |
Code function: 3_2_00451880 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, |
3_2_00451880 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Code function: 8_2_1000BA64 SetUnhandledExceptionFilter, |
8_2_1000BA64 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Messenger\Extension\WdExt.exe |
Code function: 8_2_1000BA76 SetUnhandledExceptionFilter, |
8_2_1000BA76 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_0040C6A6 SetUnhandledExceptionFilter, |
11_2_0040C6A6 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_0040C6B8 SetUnhandledExceptionFilter, |
11_2_0040C6B8 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_1000BA64 SetUnhandledExceptionFilter, |
11_2_1000BA64 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Defender\launch.exe |
Code function: 11_2_1000BA76 SetUnhandledExceptionFilter, |
11_2_1000BA76 |
Source: C:\Users\user\AppData\Local\Temp\wtmps.exe |
Code function: 14_2_00406250 SetUnhandledExceptionFilter, |
14_2_00406250 |
Source: C:\Users\user\AppData\Local\Temp\wtmps.exe |
Code function: 14_2_0040623E SetUnhandledExceptionFilter, |
14_2_0040623E |
Source: C:\Users\user\AppData\Local\Temp\wtmps.exe |
Code function: 14_2_00401AD0 SetUnhandledExceptionFilter, |
14_2_00401AD0 |
Source: C:\Windows\SysWOW64\mscaps.exe |
Code function: 15_2_00408007 SetUnhandledExceptionFilter, |
15_2_00408007 |
Source: C:\Windows\SysWOW64\mscaps.exe |
Code function: 15_2_004024A0 SetUnhandledExceptionFilter, |
15_2_004024A0 |
Source: C:\Windows\SysWOW64\mscaps.exe |
Code function: 15_2_00407FF5 SetUnhandledExceptionFilter, |
15_2_00407FF5 |