Source: Copy60330548196.exe |
Virustotal: Detection: 70% |
Perma Link |
Source: Copy60330548196.exe |
ReversingLabs: Detection: 60% |
Source: Copy60330548196.exe |
Static PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
Source: Copy60330548196.exe |
Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.142.254.109 |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /ii/Meqvrjzz.wav HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive |
Source: Copy60330548196.exe, 00000000.00000002.3911013213.0000000002B37000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://98.142.254.109 |
Source: Copy60330548196.exe |
String found in binary or memory: http://98.142.254.109/ii/Meqvrjzz.wav |
Source: Copy60330548196.exe, 00000000.00000002.3911013213.0000000002BD4000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002AD1000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002B8E000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002B82000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002B9C000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002B96000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002BDA000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002B37000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002BCC000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://98.142.254.109/ii/Meqvrjzz.wavP |
Source: Copy60330548196.exe, 00000000.00000002.3911013213.0000000002AD1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://98.142.254.109/ii/Meqvrjzz.wavt |
Source: Copy60330548196.exe, 00000000.00000002.3911013213.0000000002B7E000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002B8E000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002B82000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002B9C000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002BC4000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002B55000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002B96000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002B37000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002BCC000.00000004.00000800.00020000.00000000.sdmp, Copy60330548196.exe, 00000000.00000002.3911013213.0000000002B5C000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://98.142.254.109D |
Source: Copy60330548196.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0 |
Source: Copy60330548196.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0 |
Source: Copy60330548196.exe |
String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0 |
Source: Copy60330548196.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O |
Source: Copy60330548196.exe |
String found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05 |
Source: Copy60330548196.exe |
String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0: |
Source: Copy60330548196.exe |
String found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0L |
Source: Copy60330548196.exe |
String found in binary or memory: http://ocsp.digicert.com0C |
Source: Copy60330548196.exe |
String found in binary or memory: http://ocsp.digicert.com0N |
Source: Copy60330548196.exe |
String found in binary or memory: http://ocsp.thawte.com0 |
Source: Copy60330548196.exe |
String found in binary or memory: http://s.symcb.com/universal-root.crl0 |
Source: Copy60330548196.exe |
String found in binary or memory: http://s.symcd.com06 |
Source: Copy60330548196.exe |
String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: Copy60330548196.exe |
String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: Copy60330548196.exe, 00000000.00000002.3911013213.0000000002B37000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: Copy60330548196.exe |
String found in binary or memory: http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0( |
Source: Copy60330548196.exe |
String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0 |
Source: Copy60330548196.exe |
String found in binary or memory: http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0 |
Source: Copy60330548196.exe |
String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0( |
Source: Copy60330548196.exe |
String found in binary or memory: http://ts-ocsp.ws.symantec.com07 |
Source: Copy60330548196.exe |
String found in binary or memory: http://ts-ocsp.ws.symantec.com0; |
Source: Copy60330548196.exe |
String found in binary or memory: https://d.symcb.com/cps0% |
Source: Copy60330548196.exe |
String found in binary or memory: https://d.symcb.com/rpa0 |
Source: Copy60330548196.exe |
String found in binary or memory: https://d.symcb.com/rpa0. |
Source: Copy60330548196.exe |
String found in binary or memory: https://www.digicert.com/CPS0 |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process Stats: CPU usage > 49% |
Source: Copy60330548196.exe |
Static PE information: invalid certificate |
Source: Copy60330548196.exe, 00000000.00000002.3910279380.0000000000B7E000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameclr.dllT vs Copy60330548196.exe |
Source: Copy60330548196.exe |
Static PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
Source: classification engine |
Classification label: mal76.evad.winEXE@1/0@0/1 |
Source: Copy60330548196.exe |
Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: Copy60330548196.exe |
Static file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 50.01% |
Source: Copy60330548196.exe |
Virustotal: Detection: 70% |
Source: Copy60330548196.exe |
ReversingLabs: Detection: 60% |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: Copy60330548196.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR |
Source: Copy60330548196.exe |
Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Source: Copy60330548196.exe, UtilsInterceptorStub.cs |
.Net Code: ComputeAuthentication System.Reflection.Assembly.Load(byte[]) |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Memory allocated: 2830000 memory reserve | memory write watch |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Memory allocated: 2AD0000 memory reserve | memory write watch |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Memory allocated: 2830000 memory reserve | memory write watch |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep count: 34 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -31359464925306218s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -100000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 3656 |
Thread sleep count: 1597 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 3656 |
Thread sleep count: 8242 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -99859s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -99750s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -99640s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -99530s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -99421s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -99312s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -99203s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -99093s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -98984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -98874s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -98685s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -98577s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -98438s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -98275s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -98171s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -98051s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -97937s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -97827s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -97718s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -97609s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -97499s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -97390s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -97281s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -97171s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -97062s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -96952s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -96843s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -96734s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -96624s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -96515s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -96405s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -96296s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -96187s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -96077s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -95968s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -95859s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -95749s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -95640s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -95531s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -95421s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -95203s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -95092s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -94984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -94874s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -94765s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -94656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -94547s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe TID: 5772 |
Thread sleep time: -94437s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 100000 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 99859 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 99750 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 99640 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 99530 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 99421 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 99312 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 99203 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 99093 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 98984 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 98874 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 98685 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 98577 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 98438 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 98275 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 98171 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 98051 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 97937 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 97827 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 97718 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 97609 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 97499 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 97390 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 97281 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 97171 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 97062 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 96952 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 96843 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 96734 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 96624 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 96515 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 96405 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 96296 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 96187 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 96077 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 95968 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 95859 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 95749 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 95640 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 95531 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 95421 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 95203 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 95092 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 94984 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 94874 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 94765 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 94656 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 94547 |
Jump to behavior |
Source: C:\Users\user\Desktop\Copy60330548196.exe |
Thread delayed: delay time: 94437 |
Jump to behavior |
Source: Copy60330548196.exe, 00000000.00000002.3910279380.0000000000BDE000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll. |